ZeroHour

CVE-2026-20326

moderate

Missing Authentication (CWE-306) in Cisco Nexus Dashboard

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-20326 describes one or more missing authentication for critical function issues (CWE-306) in Cisco Nexus Dashboard, discovered by Cisco's own engineering team during a proactive internal security review rather than through external report or observed attack. Because the flaw requires no privileges and no user interaction over the network (CVSS 3.1 9.8, AV:N/PR:N/UI:N), a remote unauthenticated attacker can trigger the affected critical functionality simply by sending network requests to the device. A successful exploit carries high impact to confidentiality, integrity, and availability, consistent with full compromise of the affected function or service. All organizations running affected Cisco Nexus Dashboard releases are exposed, with internet-reachable management interfaces at greatest risk. Exploitation status is currently clean: the flaw is not in CISA's KEV and no public proof-of-concept is known, and Cisco has shipped fixes as part of a software hardening release addressing multiple internally discovered vulnerabilities.

What to do: Upgrade Nexus Dashboard to the software hardening release referenced in Cisco's PSIRT advisory (check the advisory for the exact fixed version for your release train). Until patched, restrict access to the Nexus Dashboard management interface to trusted admin networks/VPN and ensure it is not exposed to the internet, and review access logs for unauthenticated requests to sensitive endpoints.

Affected
Cisco Nexus Dashboard
Estimated exposure
moderateplausibly low tens of thousands of Nexus Dashboard deployments worldwide, of which only a small fraction (likely a few thousand clusters) have management… — Nexus Dashboard is an enterprise data-center management/control appliance typically deployed once per organization's Cisco DC estate, so total installs roughly track Cisco's enterprise data-center customer base (estimated in the tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20326 are related to missing authentication for critical function issues that are grouped under the Common Weakness Enumeration (CWE) CWE-306.

Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.