#VU124801 Storing passwords in a recoverable format in Nexus Dashboard - CVE-2026-20042
Published: April 1, 2026
Nexus Dashboard
Cisco Systems, Inc
Description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to authentication details are included in the encrypted backup files. A remote user with a valid backup file and encryption password from an affected device can decrypt the backup file and use the authentication details in the backup file to access internal-only APIs on the affected device.
Successful exploitation of the vulnerability may allow code execution as root.