Junglewise Threat Intelligence

CVE-2026-20199: Cisco ThousandEyes Virtual Appliance command injection in SSL certificate handling

CVE-2026-20199 · Severity: medium · CVSS 4.7 · Published 2026-05-20

Executive brief

A vulnerability in the Cisco ThousandEyes Virtual Appliance, a tool used for monitoring network performance, could allow an authorized administrator to take full control of the underlying system. By uploading a specially crafted security certificate, an attacker with administrative credentials can execute commands with the highest level of privileges (root). This could lead to a complete compromise of the appliance and any data it manages.

Technical details

An injection vulnerability (CWE-74) exists in the SSL certificate handling component of the Cisco ThousandEyes Virtual Appliance. The flaw is caused by insufficient validation of user-supplied input during the certificate upload process. An attacker with valid administrative credentials can exploit this by uploading a maliciously crafted certificate to the device. Successful exploitation allows for remote code execution (RCE) with root privileges on the underlying Linux operating system. Cisco has addressed this issue in ThousandEyes Virtual Appliance release 0.262.0.

Affected products

  • Cisco ThousandEyes Virtual Appliance Earlier than 0.262.0

Timeline

  • 2026-05-20: advisory: Initial public release by Cisco
  • 2026-05-20: patched: Fixed in release 0.262.0

References

Related threats