Junglewise Threat Intelligence

CVE-2026-20174: Cisco Nexus Dashboard Insights arbitrary file write in Metadata update feature

CVE-2026-20174 · Severity: medium · CVSS 4.9 · Published 2026-04-01

Technologies: Cisco Nexus Dashboard. Vendors: Cisco.

Executive brief

Cisco Nexus Dashboard Insights, a tool used for monitoring and analyzing data center network performance, contains a security flaw in its metadata update feature. An authorized administrator could upload a specially crafted file to write unauthorized data to the system's underlying operating system with the highest level of access (root). While this could lead to a full system compromise, the risk is mitigated by the fact that the attacker must already possess valid administrative credentials.

Technical details

A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights (and integrated versions within Nexus Dashboard) allows for an arbitrary file write. The root cause is insufficient validation of metadata update files during the manual upload process (CWE-22). An attacker with valid administrative credentials can exploit this by crafting a malicious metadata file and uploading it via the management interface. Successful exploitation allows the attacker to write files to any location on the underlying Linux filesystem with root-level permissions. This vulnerability affects both air-gapped and cloud-connected deployments, as the manual upload option is available in both. Cisco has released software updates to address this issue; no workarounds are available.

Affected products

  • Cisco Nexus Dashboard Insights Up to and including 6.5.0
  • Cisco Nexus Dashboard 3.1(1k) through 4.1(1g)

Timeline

  • 2026-04-01: advisory: Initial public release by Cisco
  • 2026-04-01: patched: Fixed in Nexus Dashboard 4.2.1 and later

References

Related threats