Executive brief
Cisco Nexus Dashboard, a network management platform, contains multiple critical improper access control vulnerabilities discovered during internal security review. An authenticated attacker with basic user privileges can gain unauthorized access to sensitive functions and data across the entire system, potentially compromising network infrastructure, extracting credentials, or executing unauthorized operations. The vulnerabilities affect all versions 4.2 and earlier, with patches available in version 4.3.1.175 and later.
Technical details
CVE-2026-20322 represents a grouping of internally discovered vulnerabilities classified under CWE-284 (improper access control) affecting authorization, authentication, privilege escalation, and bypass mechanisms. The vulnerability is network-accessible and requires low-privilege authentication (PR:L) with no user interaction (UI:N), allowing an authenticated attacker to achieve high impact across confidentiality, integrity, and availability with changed scope (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). This is accompanied by related CVEs covering command injection (CVE-2026-20325), missing authentication (CVE-2026-20326), information disclosure (CVE-2026-20360), SQL injection (CVE-2026-20361), and path traversal (CVE-2026-76409). Fixes are available; no workarounds exist and no public exploitation has been reported.
Affected products
- Cisco Nexus Dashboard 4.2 and earlier
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Fixed in Nexus Dashboard 4.3.1.175 and later