Junglewise Threat Intelligence

CVE-2026-20360: Cisco Nexus Dashboard information exposure and insecure handling

CVE-2026-20360 · Severity: high · CVSS 8.8 · Published 2026-09-16

Executive brief

Cisco Nexus Dashboard is a centralized management and monitoring platform used to manage Cisco network infrastructure. This advisory addresses multiple internally discovered vulnerabilities related to improper access control, command injection, missing authentication, information exposure, SQL injection, and path traversal. These flaws could allow authenticated or unauthenticated attackers to access sensitive data, execute commands, or bypass security controls depending on the specific vulnerability.

Technical details

This advisory groups six distinct vulnerabilities under a single hardening release affecting Cisco Nexus Dashboard. The vulnerabilities span multiple CWE categories: CWE-284 (improper access control), CWE-77 (command injection), CWE-306 (missing authentication), CWE-200 (information exposure), CWE-89 (SQL injection), and CWE-22 (path traversal). The vulnerabilities were discovered through internal security testing and AI-assisted analysis. Affected versions are 4.2 and earlier; fixes are available starting with version 4.3.1.175. No workarounds are available, and there is no evidence of active exploitation in the wild.

Affected products

  • Cisco Nexus Dashboard 4.2 and earlier

Timeline

  • 2026-09-16: disclosed

References

Related threats