Improper isolation or compartmentalization in Cisco NX-OS Software - CVE-2026-20032
Published: October 8, 2026
Vulnerability details
The vulnerability allows a local user to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user.
The vulnerability exists due to insufficient validation of user-supplied input in the Python interpreter of Cisco NX-OS Software when processing user-supplied input. A local user can manipulate specific functions within the Python interpreter to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user.
Exploitation requires Python execution privileges.