Improper isolation or compartmentalization in Cisco NX-OS Software - CVE-2026-20032

 

Improper isolation or compartmentalization in Cisco NX-OS Software - CVE-2026-20032

Published: October 8, 2026


Vulnerability identifier: #VU154012
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20032
CWE-ID: CWE-653
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user.

The vulnerability exists due to insufficient validation of user-supplied input in the Python interpreter of Cisco NX-OS Software when processing user-supplied input. A local user can manipulate specific functions within the Python interpreter to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user.

Exploitation requires Python execution privileges.


Affected software

Cisco NX-OS Software

How to mitigate CVE-2026-20032

Install security update from vendor's website.

Cisco NX-OS Software - addressed in versions 10.3(10), 10.4(8), 10.5(6), 10.6(4)

External References

Related Security Bulletins