Improper access control in Cisco IOS XR - CVE-2026-20279
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication or authorization and gain unauthorized access.
The vulnerability exists due to improper access control in Cisco IOS XR Software when handling access to critical functions or protected resources. A remote attacker can access critical functionality without proper authorization to bypass authentication or authorization and gain unauthorized access.
The covered issues include improper certificate validation, missing authentication for a critical function, missing authorization, and incorrect authorization.