Junglewise Threat Intelligence

CVE-2026-20206: Cisco ThousandEyes Enterprise Agent command injection in BrowserBot

CVE-2026-20206 · Severity: medium · CVSS 6.3 · Published 2026-05-20

Vendors: Cisco.

Executive brief

A vulnerability in Cisco ThousandEyes Enterprise Agent could have allowed an authorized user to execute unauthorized commands. ThousandEyes is a monitoring service used by businesses to gain visibility into network and application performance. An attacker with valid credentials could have potentially gained control over the monitoring process, though Cisco has already applied a fix to their cloud service and no customer action is required.

Technical details

An OS command injection vulnerability (CWE-78) exists in the BrowserBot component of Cisco ThousandEyes Enterprise Agent due to insufficient input validation of user-supplied command arguments. A remote attacker with valid ThousandEyes SaaS credentials and permissions to manage transaction tests could exploit this by submitting crafted input into affected parameters. Successful exploitation allows the execution of arbitrary commands within the BrowserBot container as the 'node' user. The vulnerability has been addressed by Cisco in the cloud-based service; as BrowserBot is cloud-managed, no manual updates to on-premises agents are required.

Affected products

  • Cisco ThousandEyes Enterprise Agent BrowserBot All versions prior to May 20, 2026

Timeline

  • 2026-05-20: disclosed
  • 2026-05-20: advisory
  • 2026-05-20: patched: Cisco addressed the vulnerability in the cloud-based service.

References