CVE-2026-20191: Cisco Catalyst Center Arbitrary File Read Vulnerability
A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20191?
The severity of CVE-2026-20191 is rated as high with a CVSS score of 7.5.
How does CVE-2026-20191 affect Cisco Catalyst Center?
CVE-2026-20191 allows an unauthenticated, remote attacker to read arbitrary files from a restricted container due to insufficient input validation.
How can I mitigate the risks associated with CVE-2026-20191?
To mitigate CVE-2026-20191, ensure that you apply the latest security patches provided by Cisco for the Catalyst Center.
Who can exploit CVE-2026-20191?
CVE-2026-20191 can be exploited by unauthenticated, remote attackers.
What type of attack is facilitated by CVE-2026-20191?
CVE-2026-20191 facilitates a path traversal attack allowing unauthorized file access.