Improper Neutralization of Special Elements in Output Used by a Downstream Component in Cisco IOS XE - CVE-2026-20272
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to improper neutralization of special elements in Cisco IOS XE Software when processing input. A remote attacker can send specially crafted input to execute arbitrary commands.
The issue affects Cisco IOS XE Software running in autonomous or controller mode.