ZeroHour

CVE-2026-20322

large

Critical Improper Access Control Flaws in Cisco Nexus Dashboard

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-20322 covers multiple improper access control vulnerabilities (CWE-284) in Cisco Nexus Dashboard that were found by Cisco's own engineering team during an internal security review and fixed in a software hardening release. Per the CVSS vector, exploitation requires network access and valid low-privileged credentials (AV:N/PR:L), with no user interaction, and because the scope is changed (S:C), a successful attacker can cross a security boundary to gain high-privileged access to data and functions (confidentiality, integrity, and availability all rated high). In practical terms, an attacker with any low-level authenticated account — such as a guest or limited operator account — could bypass intended access restrictions on the management platform that centralizes control of Cisco data center fabrics. All organizations running affected Cisco Nexus Dashboard deployments are in scope. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and no exploitation has been reported; specific affected and fixed version ranges are not included in the available data and must be taken from the Cisco advisory.

What to do: Check the Cisco PSIRT advisory for CVE-2026-20322 to identify whether your Nexus Dashboard release is affected and upgrade to the software hardening release it specifies. Because exploitation requires low-privileged credentials, audit the platform for unnecessary or shared low-privilege user accounts and API keys, remove them, and restrict access to the Nexus Dashboard management interface to trusted admin networks. No public PoC or in-the-wild exploitation is known, so treat this as a high-priority routine patch rather than an emergency.

Affected
Cisco Nexus Dashboard
Estimated exposure
largelikely in the low tens of thousands of Nexus Dashboard clusters worldwide (estimated; no public install or scan counts) — Nexus Dashboard is deployed roughly one management cluster per organization running Cisco ACI, NX-OS, or NDFC/Fabric Controller data center environments, and with Cisco's large enterprise data center installed base, tens of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20322 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.