Improper access control in Nexus Dashboard - CVE-2026-20322

 

Improper access control in Nexus Dashboard - CVE-2026-20322

Published: September 17, 2026


Vulnerability identifier: #VU150734
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20322
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper access control in Cisco Nexus Dashboard when accessed over a network. A remote user can access restricted functionality to compromise confidentiality, integrity, and availability.

The vulnerability was identified during internal security testing and is not known to be actively exploited.


Affected software

Nexus Dashboard

How to mitigate CVE-2026-20322

Install security update from vendor's website.

Nexus Dashboard - update to 4.3.1.175

External References

Related Security Bulletins