Junglewise Threat Intelligence

CVE-2026-20040: Cisco IOS XR Software privilege escalation in CLI

CVE-2026-20040 · Severity: high · CVSS 8.8 · Published 2026-03-11

Technologies: Cisco IOS XR Software, Cisco IOS XR. Vendors: Cisco.

Executive brief

A vulnerability in the command-line interface of Cisco IOS XR Software could allow a user with low-level access to take full control of the device. By entering specially crafted commands, an attacker can bypass security restrictions to execute unauthorized actions with root-level privileges. This could lead to a complete compromise of the networking equipment, allowing the attacker to modify configurations, access sensitive data, or disrupt network operations.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Command Line Interface (CLI) of Cisco IOS XR Software due to insufficient validation of user-supplied arguments passed to specific CLI commands. An authenticated, local attacker with low-privileged access can exploit this by executing crafted commands at the prompt. Successful exploitation allows the attacker to escape the restricted CLI environment and execute arbitrary commands on the underlying Linux-based operating system with root privileges. Cisco has released software updates (e.g., 25.2.21 and 25.4.2) to address this issue; no workarounds are available for this specific CVE.

Affected products

  • Cisco IOS XR Software All versions prior to 25.2.21, 25.3.1 prior to 25.4.2

Timeline

  • 2026-03-11: disclosed: Initial advisory publication by Cisco
  • 2026-03-11: patched: Fixed releases 25.2.21 and 25.4.2 made available

References

Related threats