Junglewise Threat Intelligence

CVE-2026-20042: Cisco Nexus Dashboard arbitrary command execution in configuration backup

CVE-2026-20042 · Severity: medium · CVSS 6.5 · Published 2026-04-01

Technologies: Cisco Nexus Dashboard. Vendors: Cisco.

Executive brief

Cisco Nexus Dashboard, a management platform for data center networks, contains a vulnerability in its configuration backup feature. If an attacker obtains a backup file and its encryption password, they can extract sensitive authentication details. This would allow them to take full control of the system, including the ability to run unauthorized commands with the highest level of administrative privileges (root).

Technical details

A vulnerability in the configuration backup feature of Cisco Nexus Dashboard arises because authentication details are improperly included within encrypted backup files. An attacker who possesses a 'Full' or 'Config-only' backup file and the corresponding encryption password can decrypt the file to retrieve these credentials. These credentials can then be used to authenticate against internal-only REST APIs. Successful exploitation allows the attacker to bypass intended access controls and execute arbitrary commands on the underlying Linux operating system with root privileges. The vulnerability is addressed in Cisco Nexus Dashboard version 4.2.1 and later.

Affected products

  • Cisco Nexus Dashboard All versions prior to 4.2.1

Timeline

  • 2026-04-01: disclosed: Initial public release of Cisco advisory
  • 2026-04-01: advisory: Cisco Security Advisory cisco-sa-nd-cbid-5YqkOSHu published
  • 2026-07-08: other: NIST initial analysis and CPE mapping completed

References

Related threats