Junglewise Threat Intelligence

CVE-2026-20326: Cisco Nexus Dashboard missing authentication for critical functions

CVE-2026-20326 · Severity: critical · CVSS 9.8 · Published 2026-09-16

Executive brief

Cisco Nexus Dashboard, a centralized management platform for network infrastructure, contains multiple missing authentication vulnerabilities discovered during an internal security review. An attacker with network access could bypass authentication controls and perform critical operations such as viewing sensitive data, modifying configurations, or disrupting service availability. Cisco has released patched software versions; no workarounds are available.

Technical details

CVE-2026-20326 is a missing authentication vulnerability (CWE-306) in Cisco Nexus Dashboard affecting versions 4.2 and earlier. The vulnerability allows an attacker with network access to invoke critical functions without proper authentication verification, potentially bypassing security controls. The root cause stems from insufficient authentication checks on sensitive operations during an internal security hardening review. An authenticated or unauthenticated remote attacker can exploit this over the network to gain unauthorized access to critical functions. Cisco has released fixed versions (4.3.1.175 for the 4.3 branch) and strongly recommends customers upgrade immediately; no workarounds exist.

Affected products

  • Cisco Nexus Dashboard 4.2 and earlier

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Fixed release 4.3.1.175 available

References

Related threats