CVE-2026-20325
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutralization of Special Elements used in a Command
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20325 are related to improper neutralization of special elements used in a command issue that are grouped under the Common Weakness Enumeration (CWE) CWE-77.
In plain language
AI Act nowCisco Nexus Dashboard has a critical flaw that lets a logged-in attacker run harmful commands; businesses using it should act now, but no fix is published yet.
CWE-77 command injection in Cisco Nexus Dashboard Software enables a low-privileged authenticated attacker to execute commands with high impact across confidentiality, integrity, and availability.
What to do now
- Check whether your organization runs Cisco Nexus Dashboard and identify all users with login access.
- No fixed version has been published; ask Cisco or your support provider for the security hardening release addressing CVE-2026-20325.
- Until a fix is available, restrict dashboard access to essential administrators and limit it to trusted internal networks.
- Review dashboard accounts and recent administrative activity for unfamiliar logins or configuration changes.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20325 and every CVE in our database. Create a free account — no credit card required.
Create Free Account