ZDI-CAN-31647: ZDI-26-719: Cisco ThousandEyes Virtual Appliance DHCP Client Command Injection Remote Code Execution Vulnerability
Published Sep 22, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco ThousandEyes Virtual Appliance. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20350.
Affected Software
1 affected component
Cisco ThousandEyes Virtual Appliance
Event History
Sep 22, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
Authentication is required. The provided information does not specify what type of authenticated account or privilege level is needed.
2
What is the potential impact if exploitation succeeds?
A remote attacker can execute arbitrary code on an affected Cisco ThousandEyes Virtual Appliance installation.
3
What identifier should be used to track this vulnerability?
The assigned CVE is CVE-2026-20350. ZDI tracks it as ZDI-26-719.