Description
A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker.

This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewall rules associated with a different user in the system.
Published: 2026-08-05
Score: 5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the network driver of Cisco Terminal Services Agent incorrectly maps network connections to user accounts, allowing an authenticated attacker to inherit another user's firewall rules. This leads to unauthorized network traffic being permitted, effectively bypassing the intended security controls. The weakness is a classic case of incorrect privilege management, classified as CWE-266.

Affected Systems

Cisco has identified the Cisco Terminal Services Agent as the affected product. The specific versions are not disclosed in the advisory, so all installations of the TS Agent that include the vulnerable network driver should be considered at risk until a patched version is deployed.

Risk and Exploitability

The vulnerability carries a CVSS score of 5, indicating medium risk. Because the exploit requires user‑level credentials and remote delivery of crafted traffic, the likelihood of exploitation depends on the presence of accounts with at least user privileges and network access to the device. No EPSS score is available and the issue is not listed in CISA KEV, implying no confirmed public exploitation yet. Nonetheless, the potential to invalidate firewall controls warrants immediate attention.

Generated by OpenCVE AI on August 5, 2026 at 18:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Cisco Terminal Services Agent firmware or patch that fixes the account‑to‑connection mapping flaw.
  • Limit account privileges to prevent unnecessary firewall rule inheritance—remove or restrict user accounts that are not needed for operation.
  • Enforce strict network segmentation and closely monitor traffic from accounts that have been mapped to critical firewall rules to detect any anomalous bypass attempts.

Generated by OpenCVE AI on August 5, 2026 at 18:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewall rules associated with a different user in the system.
Title Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-05T17:19:46.116Z

Reserved: 2025-10-08T11:59:15.352Z

Link: CVE-2026-20028

cve-icon Vulnrichment

Updated: 2026-08-05T17:19:43.317Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T19:00:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment