CVE-2026-76409
moderatePath Traversal (CWE-22) Vulnerabilities in Cisco Nexus Dashboard
CVE-2026-76409 covers multiple improper limitation of a pathname (path traversal, CWE-22) vulnerabilities in Cisco Nexus Dashboard, discovered during Cisco's internal security review and fixed via a software hardening release. A remote attacker who already holds low-privileged credentials can submit crafted pathnames that bypass directory restrictions on the appliance. Per the CVSS 8.8 (high) score, successful exploitation can yield high-impact consequences for confidentiality, integrity, and availability, potentially including arbitrary file read/write on the management platform. Organizations running Cisco Nexus Dashboard as the management control plane for their data center fabrics are affected. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and there is no evidence of exploitation in the wild.
What to do: Upgrade Cisco Nexus Dashboard to the latest hardening release referenced in Cisco's advisory, and check the advisory for the exact fixed version applicable to your deployment track. Because exploitation requires valid low-privileged credentials, enforce strong authentication and restrict management interfaces to trusted administrative networks; monitor Cisco PSIRT for updated details, as the flaw was internally found and public information is limited.
| Cisco Nexus Dashboard | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76409 are related to improper limitation of a pathname issues that are grouped under the Common Weakness Enumeration (CWE) CWE-22.
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.