Impact
CVE-2026-20326 describes a missing authentication flaw that allows unauthenticated users to access critical functions within Cisco Nexus Dashboard. The vulnerability is catalogued as CWE‑306, indicating that security controls required to prevent unauthorized access are absent. If exploited, an attacker could execute privileged commands or alter configuration settings, potentially leading to complete compromise of the affected device and the network it serves.
Affected Systems
The weakness affects Cisco Nexus Dashboard software. No specific product versions are listed, so all deployed instances of the dashboard should be considered potentially vulnerable until more detailed version information is obtained.
Risk and Exploitability
The high CVSS score of 9.8 underscores the severe impact potential of this flaw, while the EPSS score of less than 1% indicates that, at present, a large outbreak is unlikely. The vulnerability is not listed in CISA’s KEV catalog, but its authentication bypass nature makes it a prime target for attackers seeking footholds in data‑center environments. The attack vector is inferred to be via the dashboard’s management interface, so remote attackers who can reach that interface without credentials could gain unauthorized control.
OpenCVE Enrichment