ZeroHour

CVE-2026-76409

moderate

Path Traversal (CWE-22) Vulnerabilities in Cisco Nexus Dashboard

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-76409 covers multiple improper limitation of a pathname (path traversal, CWE-22) vulnerabilities in Cisco Nexus Dashboard, discovered during Cisco's internal security review and fixed via a software hardening release. A remote attacker who already holds low-privileged credentials can submit crafted pathnames that bypass directory restrictions on the appliance. Per the CVSS 8.8 (high) score, successful exploitation can yield high-impact consequences for confidentiality, integrity, and availability, potentially including arbitrary file read/write on the management platform. Organizations running Cisco Nexus Dashboard as the management control plane for their data center fabrics are affected. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and there is no evidence of exploitation in the wild.

What to do: Upgrade Cisco Nexus Dashboard to the latest hardening release referenced in Cisco's advisory, and check the advisory for the exact fixed version applicable to your deployment track. Because exploitation requires valid low-privileged credentials, enforce strong authentication and restrict management interfaces to trusted administrative networks; monitor Cisco PSIRT for updated details, as the flaw was internally found and public information is limited.

Affected
Cisco Nexus Dashboard
Estimated exposure
moderate≈10,000–100,000 appliance/VM deployments worldwide (management control plane per data center fabric), with only a subset internet-exposed — Nexus Dashboard is deployed as the centralized management platform for Cisco ACI and NX-OS data center fabrics, typically one cluster per fabric, implying tens of thousands of enterprise deployments globally, most reachable only on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76409 are related to improper limitation of a pathname issues that are grouped under the Common Weakness Enumeration (CWE) CWE-22.

Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.