SB20260917248 - Multiple vulnerabilities in Cisco Nexus Dashboard software
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2026-20322)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper access control in Cisco Nexus Dashboard when accessed over a network. A remote user can access restricted functionality to compromise confidentiality, integrity, and availability.
The vulnerability was identified during internal security testing and is not known to be actively exploited.
2) Command injection (CVE-ID: CVE-2026-20325)
CWE-ID: CWE-77 - Command injection
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper neutralization of special elements used in a command in Cisco Nexus Dashboard when processing command input. A remote user can submit specially crafted command input to compromise confidentiality, integrity, and availability.
The vulnerability was identified during internal security testing and is not known to be actively exploited.
3) Missing Authentication for Critical Function (CVE-ID: CVE-2026-20326)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to missing authentication for a critical function in Cisco Nexus Dashboard when accessing critical functionality over a network. A remote user can access critical functionality to compromise confidentiality, integrity, and availability.
The vulnerability was identified during internal security testing and is not known to be actively exploited.
4) Information disclosure (CVE-ID: CVE-2026-20360)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to exposure of sensitive information to an unauthorized actor in Cisco Nexus Dashboard when accessed over a network. A remote user can leverage exposed sensitive information to compromise confidentiality, integrity, and availability.
The vulnerability was identified during internal security testing and is not known to be actively exploited.
5) SQL injection (CVE-ID: CVE-2026-20361)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in Cisco Nexus Dashboard when processing SQL input. A remote user can submit specially crafted SQL input to compromise confidentiality, integrity, and availability.
The vulnerability was identified during internal security testing and is not known to be actively exploited.
6) Path traversal (CVE-ID: CVE-2026-76409)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in Cisco Nexus Dashboard when processing pathnames. A remote user can submit a crafted pathname to compromise confidentiality, integrity, and availability.
The vulnerability was identified during internal security testing and is not known to be actively exploited.
Remediation
Install update from vendor's website.