Impact
CVE-2026-20325 represents a command injection vulnerability caused by improper neutralization of special elements in command processing. Attackers could supply crafted input that bypasses validation, allowing arbitrary command execution on the underlying system, leading to full system compromise. The weakness follows the Common Weakness Enumeration identifier CWE-77.
Affected Systems
The vulnerability affects Cisco Nexus Dashboard software. The specific affected release versions are not detailed in the advisory, but the issue was mitigated in the September 2026 hardening release. Organizations running any version of Cisco Nexus Dashboard should verify whether their product is part of the patched update.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.9, indicating a very high severity. However, the EPSS score is listed as < 1 %, meaning the likelihood of exploitation in the wild is very low. The vulnerability is not currently listed in CISA’s KEV catalog. Likely attack vectors involve remote exploitation through exposed management interfaces where command parameters are not properly sanitized.
OpenCVE Enrichment