Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20322 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
Published: 2026-09-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized privileged access
Action: Apply Patch
AI Analysis

Impact

The vulnerability in Cisco Nexus Dashboard is an improper access control flaw that can allow an attacker to gain unauthorized privileged access to the system. This weakness is classified as CWE-284 and may enable escalation of privileges or bypass of security controls, potentially compromising the confidentiality, integrity, and availability of the managed network infra.

Affected Systems

Affected vendors include Cisco, specifically the Cisco Nexus Dashboard product line. No specific version information is provided in the advisory, so the issue is considered present in all releases prior to the September 2026 hardening update.

Risk and Exploitability

The CVSS score of 9.9 indicates critical severity. The EPSS score of less than 1% suggests a very low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote access over the network where authentication or authorization checks are improperly enforced, which is inferred from the nature of an access control flaw and the absence of local-only qualifiers in the description. Excessive risk remains if systems remain unpatched, especially for administrators or services exposed to untrusted networks.

Generated by OpenCVE AI on September 18, 2026 at 00:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Cisco Nexus Dashboard hardening release from September 2026 that contains the corrected access control checks
  • Ensure that all administrative interfaces require proper authentication and that role‑based permissions are enforced for all privileged functions
  • Conduct an audit of the access control policies to verify that no privileged resources are reachable by users lacking appropriate authorization

Generated by OpenCVE AI on September 18, 2026 at 00:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco nexus Dashboard
Vendors & Products Cisco
Cisco nexus Dashboard

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard&nbsp;engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20322 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
Title Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access Control
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Nexus Dashboard
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T13:41:16.925Z

Reserved: 2025-10-08T11:59:15.411Z

Link: CVE-2026-20322

cve-icon Vulnrichment

Updated: 2026-09-18T13:32:49.456Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:23.040

Modified: 2026-09-18T14:17:16.333

Link: CVE-2026-20322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:48Z

Weaknesses