Path traversal in Nexus Dashboard - CVE-2026-76409

 

Path traversal in Nexus Dashboard - CVE-2026-76409

Published: September 17, 2026


Vulnerability identifier: #VU150739
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76409
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in Cisco Nexus Dashboard when processing pathnames. A remote user can submit a crafted pathname to compromise confidentiality, integrity, and availability.

The vulnerability was identified during internal security testing and is not known to be actively exploited.


Affected software

Nexus Dashboard

How to mitigate CVE-2026-76409

Install security update from vendor's website.

Nexus Dashboard - update to 4.3.1.175

External References

Related Security Bulletins