Threat Advisory

Cisco Nexus Dashboard Software Flaws Expose Sensitive Information

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Cisco Nexus Dashboard Software, with a high overall risk and impact due to potential exploitation by unauthorized actors. The affected version range is 4.2 and earlier and 4.3.

CVE-2026-20322 (CVSS 9.9 — Severity): Improper access control vulnerability allows attackers to bypass authorization, authentication, privileges, and access controls.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Cisco Nexus Dashboard Software, with a high overall risk and impact due to potential exploitation by unauthorized actors. The affected version range is 4.2 and earlier and 4.3.

CVE-2026-20322 (CVSS 9.9 — Severity): Improper access control vulnerability allows attackers to bypass authorization, authentication, privileges, and access controls.[emaillocker id="1283"]

CVE-2026-20325 (CVSS 9.9 — Severity): Improper neutralization of special elements used in a command vulnerability enables command injection, code injection, and expression/template injection attacks.

CVE-2026-20326 (CVSS 9.8 — Severity): Missing authentication for critical function vulnerability allows unauthorized actors to access sensitive information without proper verification.

CVE-2026-20360 (CVSS 8.8 — Severity): Exposure of sensitive information to an unauthorized actor vulnerability involves cleartext storage, insecure resource exposure, and privilege issues.

CVE-2026-20361 (CVSS 8.8 — Severity): Improper neutralization of special elements used in an SQL command vulnerability enables SQL injection attacks with associated error/info disclosure and unsafe defaults.

CVE-2026-76409 (CVSS 8.8 — Severity): Improper limitation of a pathname to a restricted directory vulnerability involves path traversal and external control of file path.

These vulnerabilities collectively present a significant risk, particularly for organizations that have not yet upgraded their Cisco Nexus Dashboard Software.

RECOMMENDATION:

We recommend you to update Cisco Nexus Dashboard to version 4.3.1.175.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu