Improper Neutralization of Special Elements in Output Used by a Downstream Component in Cisco IOS XE - CVE-2026-20272

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Cisco IOS XE - CVE-2026-20272

Published: August 6, 2026


Vulnerability identifier: #VU141052
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20272
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary commands.

The vulnerability exists due to improper neutralization of special elements in Cisco IOS XE Software when processing input. A remote attacker can send specially crafted input to execute arbitrary commands.

The issue affects Cisco IOS XE Software running in autonomous or controller mode.


Affected software

Cisco IOS XE

How to mitigate CVE-2026-20272

Install security update from vendor's website.

Cisco IOS XE - addressed in versions 17.9.10, 17.12.8, 17.15.6, 17.18.4, 17.18.4a, 26.1.2

External References

Related Security Bulletins