Junglewise Threat Intelligence

CVE-2026-20267: Cisco IOS XE Software improper access control

CVE-2026-20267 · Severity: critical · CVSS 9 · Published 2026-08-05

Executive brief

Cisco IOS XE is a network operating system used in Cisco switches and routers to manage data traffic and network security. A critical vulnerability in access control allows attackers to bypass authentication or authorization checks without requiring any credentials, potentially gaining full control over affected devices. This could lead to unauthorized access to sensitive network infrastructure, data theft, or service disruption.

Technical details

CVE-2026-20267 is an improper access control vulnerability (CWE-284) discovered during Cisco's internal security review and grouped with related hardening issues under a single CVE identifier. The vulnerability affects Cisco IOS XE Software running in both autonomous and controller mode across multiple release families (17.9, 17.12, 17.15, 17.18, and 26.1), with the exception of Catalyst 3650 and 3850 Series Switches. The flaw allows network-accessible attackers to bypass access controls without authentication, achieving confidentiality, integrity, and availability impact (CVSS 9.0, vector AV:N/AC:L/PR:N/UI:N). Cisco has released patched versions: 17.9.10, 17.12.8, 17.15.6, 17.18.4/4a, and 26.1.2. No workarounds are available.

Affected products

  • Cisco IOS XE Software 17.9 (before 17.9.10), 17.12 (before 17.12.8), 17.15 (before 17.15.6), 17.18 (before 17.18.4), 26.1 (before 26.1.2)

Timeline

  • 2026-08-05: disclosed
  • 2026-08-05: patched: Patch released same day as disclosure

References

Related threats