CVE-2026-20361
Last modified
CVE-2026-20361 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20361 are related to SQL injection issues that are grouped under the Common Weakness Enumeration (CWE) CWE-89..
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20361 are related to SQL injection issues that are grouped under the Common Weakness Enumeration (CWE) CWE-89.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Nexus Dashboard | 2.1(1d); 2.1(1e); 2.1(2d); 2.2(1h); 2.2(1e); 2.2(2d); 2.1(2f); 2.3(1c); 2.3(2b); 2.3(2c); 2.3(2d); 2.3(2e); 3.0(1f); 3.0(1i); 3.1(1k); 3.1(1l); 3.2(1e); 3.2(1i); 3.3(1a); 3.3(1b); 3.3(2b); 4.0(1i); 3.3(2g); 3.2(2f); 3.2(2g); 3.2(2m); 3.1(1n); 4.1(1g); 4.2.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-20361?
How severe is CVE-2026-20361?
How do I fix CVE-2026-20361?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-20355Multiple vulnerabilities in the Secure/Multipurpose Internet…5.9
- CVE-2026-20357As part of Cisco's ongoing commitment to proactive security …10
- CVE-2026-20358As part of Cisco's ongoing commitment to proactive security …10
- CVE-2026-20359As part of Cisco's ongoing commitment to proactive security …9.9
- CVE-2026-2036GFI Archiver MArc.Store Deserialization of Untrusted Data Re…8.8
- CVE-2026-20360As part of Cisco's ongoing commitment to proactive security …8.8
- CVE-2026-2037GFI Archiver MArc.Core Deserialization of Untrusted Data Rem…8.8
- CVE-2026-2038GFI Archiver MArc.Core Missing Authorization Authentication …9.8
- CVE-2026-2039GFI Archiver MArc.Store Missing Authorization Authentication…9.8
- CVE-2026-2040PDF-XChange Editor TrackerUpdate Uncontrolled Search Path El…7.3
- CVE-2026-20401In Modem, there is a possible system crash due to an uncaugh…7.5
- CVE-2026-20402In Modem, there is a possible system crash due to improper i…6.5
Are you affected by CVE-2026-20361?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
