Executive brief
Cisco Nexus Dashboard, a centralized management platform for network infrastructure, contains multiple missing authentication vulnerabilities discovered during an internal security review. An attacker with network access could bypass authentication controls and perform critical operations such as viewing sensitive data, modifying configurations, or disrupting service availability. Cisco has released patched software versions; no workarounds are available.
Technical details
CVE-2026-20326 is a missing authentication vulnerability (CWE-306) in Cisco Nexus Dashboard affecting versions 4.2 and earlier. The vulnerability allows an attacker with network access to invoke critical functions without proper authentication verification, potentially bypassing security controls. The root cause stems from insufficient authentication checks on sensitive operations during an internal security hardening review. An authenticated or unauthenticated remote attacker can exploit this over the network to gain unauthorized access to critical functions. Cisco has released fixed versions (4.3.1.175 for the 4.3 branch) and strongly recommends customers upgrade immediately; no workarounds exist.
Affected products
- Cisco Nexus Dashboard 4.2 and earlier
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Fixed release 4.3.1.175 available