SB20260917248 - Multiple vulnerabilities in Cisco Nexus Dashboard software



SB20260917248 - Multiple vulnerabilities in Cisco Nexus Dashboard software

Published: September 17, 2026

Security Bulletin ID SB20260917248
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 6
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 6 vulnerabilities.


1) Improper access control (CVE-ID: CVE-2026-20322)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper access control in Cisco Nexus Dashboard when accessed over a network. A remote user can access restricted functionality to compromise confidentiality, integrity, and availability.

The vulnerability was identified during internal security testing and is not known to be actively exploited.


2) Command injection (CVE-ID: CVE-2026-20325)

CWE-ID: CWE-77 - Command injection

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper neutralization of special elements used in a command in Cisco Nexus Dashboard when processing command input. A remote user can submit specially crafted command input to compromise confidentiality, integrity, and availability.

The vulnerability was identified during internal security testing and is not known to be actively exploited.


3) Missing Authentication for Critical Function (CVE-ID: CVE-2026-20326)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to missing authentication for a critical function in Cisco Nexus Dashboard when accessing critical functionality over a network. A remote user can access critical functionality to compromise confidentiality, integrity, and availability.

The vulnerability was identified during internal security testing and is not known to be actively exploited.


4) Information disclosure (CVE-ID: CVE-2026-20360)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to exposure of sensitive information to an unauthorized actor in Cisco Nexus Dashboard when accessed over a network. A remote user can leverage exposed sensitive information to compromise confidentiality, integrity, and availability.

The vulnerability was identified during internal security testing and is not known to be actively exploited.


5) SQL injection (CVE-ID: CVE-2026-20361)

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper neutralization of special elements used in an SQL command in Cisco Nexus Dashboard when processing SQL input. A remote user can submit specially crafted SQL input to compromise confidentiality, integrity, and availability.

The vulnerability was identified during internal security testing and is not known to be actively exploited.


6) Path traversal (CVE-ID: CVE-2026-76409)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in Cisco Nexus Dashboard when processing pathnames. A remote user can submit a crafted pathname to compromise confidentiality, integrity, and availability.

The vulnerability was identified during internal security testing and is not known to be actively exploited.


Remediation

Install update from vendor's website.