Improper access control in Cisco IOS XR - CVE-2026-20279

 

Improper access control in Cisco IOS XR - CVE-2026-20279

Published: September 2, 2026


Vulnerability identifier: #VU146769
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20279
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication or authorization and gain unauthorized access.

The vulnerability exists due to improper access control in Cisco IOS XR Software when handling access to critical functions or protected resources. A remote attacker can access critical functionality without proper authorization to bypass authentication or authorization and gain unauthorized access.

The covered issues include improper certificate validation, missing authentication for a critical function, missing authorization, and incorrect authorization.


Affected software

Cisco IOS XR

How to mitigate CVE-2026-20279

Install security update from vendor's website.

Cisco IOS XR - addressed in versions 26.2.2, 26.3.1

External References

Related Security Bulletins