Command injection in Nexus Dashboard - CVE-2026-20325
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper neutralization of special elements used in a command in Cisco Nexus Dashboard when processing command input. A remote user can submit specially crafted command input to compromise confidentiality, integrity, and availability.
The vulnerability was identified during internal security testing and is not known to be actively exploited.