Improper access control in Cisco IOS XE - CVE-2026-20267
Published: August 6, 2026 / Updated: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to bypass access controls.
The vulnerability exists due to improper access control in Cisco IOS XE Software when handling requests. A remote authenticated user can send a specially crafted request to bypass access controls.
The issue affects Cisco IOS XE Software running in autonomous or controller mode.