CVE-2026-20325
Last modified
CVE-2026-20325 is a critical-severity vulnerability rated 9.9/10 on the CVSS scale. As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20325 are related to improper neutralization of special elements used in a command issue that are grouped under the Common Weakness Enumeration (CWE) CWE-77..
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20325 are related to improper neutralization of special elements used in a command issue that are grouped under the Common Weakness Enumeration (CWE) CWE-77.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Nexus Dashboard | 2.1(1d); 2.1(1e); 2.1(2d); 2.2(1h); 2.2(1e); 2.2(2d); 2.1(2f); 2.3(1c); 2.3(2b); 2.3(2c); 2.3(2d); 2.3(2e); 3.0(1f); 3.0(1i); 3.1(1k); 3.1(1l); 3.2(1e); 3.2(1i); 3.3(1a); 3.3(1b); 3.3(2b); 4.0(1i); 3.3(2g); 3.2(2f); 3.2(2g); 3.2(2m); 3.1(1n); 4.1(1g); 4.2.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-20325?
How severe is CVE-2026-20325?
How do I fix CVE-2026-20325?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-20319As part of Cisco's ongoing commitment to proactive security …7.5
- CVE-2026-2032Malicious scripts that interrupt new tab page loading could …4.3
- CVE-2026-20320A vulnerability in the Open Client Interface (OCI) XML Parse…7.5
- CVE-2026-20322As part of Cisco's ongoing commitment to proactive security …9.9
- CVE-2026-20323A vulnerability in the sftunnel inter-device communication p…8.3
- CVE-2026-20324A vulnerability in the sftunnel inter-device communication p…9.9
- CVE-2026-20326As part of Cisco's ongoing commitment to proactive security …9.8
- CVE-2026-20327A vulnerability in the web-based management interface of Cis…6.5
- CVE-2026-20329As part of Cisco's ongoing commitment to proactive security …9.9
- CVE-2026-2033MLflow Tracking Server Artifact Handler Directory Traversal …8.1
- CVE-2026-20330As part of Cisco's ongoing commitment to proactive security …9.9
- CVE-2026-20331As part of Cisco's ongoing commitment to proactive security …9.6
Are you affected by CVE-2026-20325?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
