Executive brief
Cisco Nexus Dashboard, a centralized management platform for Cisco data center infrastructure, contains multiple security vulnerabilities grouped under a comprehensive hardening release. These vulnerabilities span path traversal attacks, missing authentication, command injection, and improper access controls, potentially allowing attackers to bypass security restrictions, execute arbitrary commands, or access sensitive configuration data. The vulnerabilities were discovered during internal security review and are not currently known to be exploited in the wild, but patches are available and customers should upgrade immediately.
Technical details
This advisory groups six related vulnerabilities (CVE-2026-76409, CVE-2026-20322, CVE-2026-20325, CVE-2026-20326, CVE-2026-20360, CVE-2026-20361) across multiple CWE categories including path traversal (CWE-22), improper access control (CWE-284), command injection (CWE-77), missing authentication (CWE-306), information disclosure (CWE-200), and SQL injection (CWE-89). The primary CVE-2026-76409 involves improper path limitation allowing directory traversal attacks. The vulnerabilities require authentication in most cases (indicated by CVSS profile AV:N/AC:L/PR:L) and are exploitable over the network. Cisco has released patched versions (Nexus Dashboard 4.3.1.175 and later) with no workarounds available; customers must upgrade from releases 4.2 and earlier.
Affected products
- Cisco Nexus Dashboard 4.2 and earlier
Timeline
- 2026-09-16: disclosed: Security advisory published by Cisco PSIRT
- 2026-09-16: patched: Fixed releases available: Nexus Dashboard 4.3.1.175 and later