Executive brief
Cisco Nexus Dashboard is a centralized management and orchestration platform for data center networks. A command injection vulnerability (CVE-2026-20325) allows authenticated users to execute arbitrary commands, potentially compromising the entire managed infrastructure. This vulnerability is part of a suite of critical flaws discovered during internal security review and requires immediate patching to maintain network security.
Technical details
CVE-2026-20325 is a command injection vulnerability (CWE-77) in Cisco Nexus Dashboard caused by improper neutralization of special elements used in commands. The vulnerability requires authenticated access (PR:L in CVSS vector) and has network attack vector (AV:N). An attacker with valid credentials can inject arbitrary commands through the application interface to achieve remote code execution with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). The scope is changed (S:C), indicating the vulnerability can affect resources beyond the vulnerable component. Cisco released fixed versions 4.3.1.175 and later; versions 4.2 and earlier are vulnerable with no available workarounds.
Affected products
- Cisco Nexus Dashboard 4.2 and earlier
Timeline
- 2026-09-16: disclosed