ZeroHour

CVE-2026-20361

moderate

SQL Injection in Cisco Nexus Dashboard

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Cisco Nexus Dashboard contains SQL injection flaws (CWE-89) that were found during an internal Cisco security review and are addressed in a software hardening release. A remote attacker who already holds low-privilege credentials can send crafted input to a vulnerable interface, causing arbitrary SQL queries against the backend database. Successful exploitation could expose or tamper with sensitive data and potentially disrupt the service, consistent with the high CVSS 3.1 score of 8.8. Any organization running an affected Cisco Nexus Dashboard release is exposed; specific affected and fixed version ranges are provided in Cisco's PSIRT advisory. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and no exploitation has been reported.

What to do: Upgrade Nexus Dashboard to the hardened release identified in Cisco's PSIRT advisory for CVE-2026-20361 (exact fixed version numbers are not included in the available data). Because exploitation requires low-privilege authenticated access, restrict management interfaces to trusted admin networks, review accounts with low-privilege roles, and check logs for unexpected database-oriented requests. Monitor the Cisco advisory for updated fixed-version and mitigation guidance.

Affected
Cisco Nexus Dashboard
Estimated exposure
moderate≈1,000–10,000 enterprise data-center deployments (a small fraction of them internet-exposed) — Nexus Dashboard is a specialized data-center management/orchestration appliance typically deployed inside enterprise networks rather than at internet scale, so the plausible install base is on the order of thousands of deployments, with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20361 are related to SQL injection issues that are grouped under the Common Weakness Enumeration (CWE) CWE-89.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.