SQL injection in Nexus Dashboard - CVE-2026-20361
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in Cisco Nexus Dashboard when processing SQL input. A remote user can submit specially crafted SQL input to compromise confidentiality, integrity, and availability.
The vulnerability was identified during internal security testing and is not known to be actively exploited.