Improper Neutralization of Special Elements in Output Used by a Downstream Component in Cisco ThousandEyes Virtual Appliance - CVE-2026-20199
Published: May 21, 2026
Cisco ThousandEyes Virtual Appliance
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to insufficient validation of user-supplied input in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance when uploading a certificate. A remote privileged user can upload a crafted certificate to execute arbitrary code.
Successful exploitation could result in code execution on the underlying operating system as the root user.