SB2026040175 - Arbitrary file write in Cisco Nexus Dashboard Insights
Published: April 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Path traversal (CVE-ID: CVE-2026-20174)
The vulnerability allows a remote user to write arbitrary files to an affected system.
The vulnerability exists due to input validation error when processing directory traversal sequences in the Metadata update feature. A remote privileged user can write arbitrary files to the underlying operating system as the root user.
Remediation
Install update from vendor's website.