CVE-2026-20322
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access Control
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20322 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
In plain language
AI Act nowCisco Nexus Dashboard has a critical access-control flaw affecting logged-in users; typical small businesses should act promptly if they run it.
Improper access control in Cisco Nexus Dashboard allows a low-privileged authenticated attacker over the network to compromise confidentiality, integrity, and availability.
What to do now
- Confirm whether your organization runs Cisco Nexus Dashboard and identify every version in use.
- Review user accounts and remove or disable any that are no longer needed.
- No fixed version has been published; ask Cisco or your support provider for the security-hardening release that addresses CVE-2026-20322.
- Restrict dashboard access to trusted administrators and management networks until an update is available.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20322 and every CVE in our database. Create a free account — no credit card required.
Create Free Account