CVE-2026-20104
Last modified
CVE-2026-20104 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE9320 Rugged Series Switches, and Cisco IE3500 and IE3505 Rugged Series Switches could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an affected device to execute arbitrary code at boot time and break the chain of trust. This vulnerability is due to insufficient validation of software at boot time. An attacker could exploit this vulnerability by manipulating the loaded binaries on an affected device to bypass some of the integrity checks that are performed during the boot process. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE9320 Rugged Series Switches, and Cisco IE3500 and IE3505 Rugged Series Switches could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an affected device to execute arbitrary code at boot time and break the chain of trust. This vulnerability is due to insufficient validation of software at boot time. An attacker could exploit this vulnerability by manipulating the loaded binaries on an affected device to bypass some of the integrity checks that are performed during the boot process. A successful exploit could allow the attacker to execute code that bypasses the requirement to run Cisco-signed images. Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates because this vulnerability allows an attacker to bypass a major security feature of a device.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco IOS XE Software | 16.12.8; 16.12.6; 16.12.6a; 16.12.7; 17.3.3; 17.3.4; 17.3.5; 17.3.6; 17.3.4b; 17.3.7; 17.3.8; 17.3.8a; 17.4.1; 17.5.1; 17.6.1; 17.6.2; 17.6.3; 17.6.1y; 17.6.4; 17.6.5; 17.6.6; 17.6.6a; 17.6.5a; 17.6.7; 17.6.8; 17.7.1; 17.7.1a; 17.10.1; 17.8.1; 17.8.1a; 17.9.1; 17.9.2; 17.9.1a; 17.9.3; 17.9.4; 17.9.5; 17.9.4a; 17.9.5b; 17.9.6; 17.9.6a; 17.9.7; 17.9.8; 17.11.1; 17.12.1; 17.12.2; 17.12.3; 17.12.4; 17.12.5; 17.12.6; 17.13.1; 17.14.1; 17.15.1; 17.15.2; 17.15.3; 17.15.4; 17.16.1; 17.17.1; 17.18.1; 17.18.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-20104?
How severe is CVE-2026-20104?
How do I fix CVE-2026-20104?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-20099A vulnerability in the web-based management interface of Cis…6.7
- CVE-2026-2010A vulnerability has been found in Sanluan PublicCMS up to 4.…4.2
- CVE-2026-20100A vulnerability in the LUA interperter of the Remote Access …7.7
- CVE-2026-20101A vulnerability in the SAML 2.0 single sign-on (SSO) feature…8.6
- CVE-2026-20102A vulnerability in the SAML 2.0 single sign-on (SSO) feature…6.1
- CVE-2026-20103A vulnerability in the Remote Access SSL VPN functionality o…8.6
- CVE-2026-20105A vulnerability in the Remote Access SSL VPN functionality o…7.7
- CVE-2026-20106A vulnerability in the Remote Access SSL VPN, HTTP managemen…5.3
- CVE-2026-20107A vulnerability in the Object Model CLI component of Cisco A…5.5
- CVE-2026-20108A vulnerability in the web-based management interface of Cis…5.4
- CVE-2026-20109Multiple vulnerabilities in the web-based management interfa…4.8
- CVE-2026-2011A vulnerability was found in itsourcecode Student Management…9.8
Are you affected by CVE-2026-20104?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
