Multiple security vulnerabilities have been identified in Cisco Nexus Dashboard Software, with a high overall risk and impact due to potential exploitation by unauthorized actors. The affected version range is 4.2 and earlier and 4.3.
CVE-2026-20322 (CVSS 9.9 — Severity): Improper access control vulnerability allows attackers to bypass authorization, authentication, privileges, and access controls.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in Cisco Nexus Dashboard Software, with a high overall risk and impact due to potential exploitation by unauthorized actors. The affected version range is 4.2 and earlier and 4.3.
CVE-2026-20322 (CVSS 9.9 — Severity): Improper access control vulnerability allows attackers to bypass authorization, authentication, privileges, and access controls.[emaillocker id="1283"]
CVE-2026-20325 (CVSS 9.9 — Severity): Improper neutralization of special elements used in a command vulnerability enables command injection, code injection, and expression/template injection attacks.
CVE-2026-20326 (CVSS 9.8 — Severity): Missing authentication for critical function vulnerability allows unauthorized actors to access sensitive information without proper verification.
CVE-2026-20360 (CVSS 8.8 — Severity): Exposure of sensitive information to an unauthorized actor vulnerability involves cleartext storage, insecure resource exposure, and privilege issues.
CVE-2026-20361 (CVSS 8.8 — Severity): Improper neutralization of special elements used in an SQL command vulnerability enables SQL injection attacks with associated error/info disclosure and unsafe defaults.
CVE-2026-76409 (CVSS 8.8 — Severity): Improper limitation of a pathname to a restricted directory vulnerability involves path traversal and external control of file path.
These vulnerabilities collectively present a significant risk, particularly for organizations that have not yet upgraded their Cisco Nexus Dashboard Software.
We recommend you to update Cisco Nexus Dashboard to version 4.3.1.175.
The following reports contain further technical details:
[/emaillocker]