CVE-2026-20322: Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access Control
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20322 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges. Exploitation does not require user interaction and can be performed over the network.
What is the potential impact if exploitation succeeds?
The reported CVSS vector indicates high impacts to confidentiality, integrity, and availability, with scope changed. This means the issue could affect resources beyond the initially vulnerable security authority.