Junglewise Threat Intelligence

CVE-2026-20325: Cisco Nexus Dashboard command injection vulnerability

CVE-2026-20325 · Severity: critical · CVSS 9.9 · Published 2026-09-16

Executive brief

Cisco Nexus Dashboard is a centralized management and orchestration platform for data center networks. A command injection vulnerability (CVE-2026-20325) allows authenticated users to execute arbitrary commands, potentially compromising the entire managed infrastructure. This vulnerability is part of a suite of critical flaws discovered during internal security review and requires immediate patching to maintain network security.

Technical details

CVE-2026-20325 is a command injection vulnerability (CWE-77) in Cisco Nexus Dashboard caused by improper neutralization of special elements used in commands. The vulnerability requires authenticated access (PR:L in CVSS vector) and has network attack vector (AV:N). An attacker with valid credentials can inject arbitrary commands through the application interface to achieve remote code execution with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). The scope is changed (S:C), indicating the vulnerability can affect resources beyond the vulnerable component. Cisco released fixed versions 4.3.1.175 and later; versions 4.2 and earlier are vulnerable with no available workarounds.

Affected products

  • Cisco Nexus Dashboard 4.2 and earlier

Timeline

  • 2026-09-16: disclosed

References

Related threats