Junglewise Threat Intelligence

CVE-2026-20361: Cisco Nexus Dashboard SQL injection vulnerability

CVE-2026-20361 · Severity: high · CVSS 8.8 · Published 2026-09-16

Executive brief

Cisco Nexus Dashboard, a centralized management and orchestration platform for Cisco's data center networking infrastructure, contains SQL injection vulnerabilities that could allow an authenticated attacker to access or modify sensitive database information. An attacker with valid credentials could craft malicious SQL commands to bypass authentication controls, extract confidential data, or corrupt the database, potentially disrupting network operations across managed infrastructure.

Technical details

CVE-2026-20361 is a SQL injection vulnerability (CWE-89) in Cisco Nexus Dashboard resulting from improper neutralization of special characters in SQL commands. The vulnerability requires network access and valid authentication credentials to exploit. An authenticated attacker can inject malicious SQL syntax into application input fields to execute arbitrary database queries, leading to unauthorized data disclosure, data modification, or potential code execution depending on database permissions. Cisco has released fixed software versions (4.3.1.175 and later for version 4.3; migration required for 4.2 and earlier) with no known public exploits or active exploitation in the wild.

Affected products

  • Cisco Nexus Dashboard 4.2 and earlier; 4.3 before 4.3.1.175

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: advisory: Cisco advisory cisco-sa-hardening-ndw1-psFvnrg published

References

Related threats