CVE-2026-20325: Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutralization of Special Elements used in a Command
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20325 are related to improper neutralization of special elements used in a command issue that are grouped under the Common Weakness Enumeration (CWE) CWE-77.
Affected Software
Event History
Frequently Asked Questions
What access would an attacker need to exploit this issue?
The CVSS vector indicates network access, low attack complexity, low privileges required, and no user interaction. An attacker would need an existing low-privilege account or access level before attempting exploitation.
What could successful exploitation impact?
The reported CVSS metrics indicate high confidentiality, integrity, and availability impact, with scope changed. This means a successful attack could potentially affect resources beyond the initially vulnerable security authority.