Improper Neutralization of Special Elements in Output Used by a Downstream Component in Cisco ThousandEyes Virtual Appliance - CVE-2026-20199

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Cisco ThousandEyes Virtual Appliance - CVE-2026-20199

Published: May 21, 2026


Vulnerability identifier: #VU132082
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20199
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to insufficient validation of user-supplied input in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance when uploading a certificate. A remote privileged user can upload a crafted certificate to execute arbitrary code.

Successful exploitation could result in code execution on the underlying operating system as the root user.


Affected software

Cisco ThousandEyes Virtual Appliance

How to mitigate CVE-2026-20199

Install security update from vendor's website.

Cisco ThousandEyes Virtual Appliance - update to 0.262.0

External References

Related Security Bulletins