Junglewise Threat Intelligence

CVE-2026-5944: Cisco Intersight Device Connector improper access control in Nutanix Prism Central

CVE-2026-5944 · Severity: high · CVSS 8.2 · Published 2026-04-28

Vendors: Cisco.

Executive brief

A security vulnerability exists in the Cisco Intersight Device Connector used with Nutanix Prism Central, a tool for managing data center infrastructure. An unauthorized person on the network can access a management interface that should be protected, allowing them to view details about virtual machines and cluster configurations. While they cannot steal user passwords, they can trigger maintenance tasks that could shut down or disrupt active business services and applications.

Technical details

An improper access control vulnerability (CWE-306/CWE-862) exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an unauthenticated API passthrough endpoint on TCP port 7373 within the deployment's network scope. An unauthenticated attacker can send crafted requests to this endpoint to enumerate cluster metadata, including virtual machine information and cluster configuration details. While the API is primarily read-only, it also permits the invocation of certain cluster maintenance workflows. Exploitation can lead to the disruption of active workloads and loss of service availability, though it does not grant access to credentials or persistent system configuration modification. The vulnerability affects versions 4.3.0 through 7.5.0.

Affected products

  • Cisco Intersight Device Connector for Nutanix Prism Central 4.3.0 to 7.5.0

Timeline

  • 2026-04-28: disclosed
  • 2026-04-28: advisory

References