Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20360 are related to information exposure and insecure handling issues that are grouped under the Common Weakness Enumeration (CWE) CWE-200.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Exposure
Action: Apply Patch
AI Analysis

Impact

A vulnerability classified as CWE-200 exposes sensitive information through insecure handling within the Cisco Nexus Dashboard. If exploited, an attacker could access privileged data that should be protected, potentially compromising confidentiality and allowing further compromise of network resources. The weakness stems from improper protection of data in transit or storage, and does not directly enable code execution, but the disclosed information could enable social engineering, credential theft, or assistance in other attacks.

Affected Systems

The Cisco Nexus Dashboard product is affected by the hardening release issued in September 2026. No specific version ranges are provided, so all installations of Cisco Nexus Dashboard that have not yet applied the release are assumed vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, reducing evidence of active exploitation. Based on the nature of the software and the lack of authentication bypass, the likely attack vector is a network-based attack where the attacker sends a crafted request to the dashboard service to trigger the information leak. The vulnerability can be exploited without requiring successful privileged access, however disclosure of sensitive data can enable further attacks.

Generated by OpenCVE AI on September 17, 2026 at 22:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Cisco Nexus Dashboard hardening release September 2026 that addresses the information exposure issue.
  • Review and adjust dashboard configuration to ensure that only authorized users can view sensitive data and that data is properly masked or restricted in logs and dashboards.
  • Investigate any unexpected data visibility or export capabilities and monitor logs for anomalous access patterns that could indicate exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 22:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco nexus Dashboard
Vendors & Products Cisco
Cisco nexus Dashboard

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20360 are related to information exposure and insecure handling issues that are grouped under the Common Weakness Enumeration (CWE) CWE-200.
Title Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Information Exposure & Insecure Handling
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cisco Nexus Dashboard
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T03:56:11.282Z

Reserved: 2025-10-08T11:59:15.414Z

Link: CVE-2026-20360

cve-icon Vulnrichment

Updated: 2026-09-17T13:36:25.295Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:12.640

Modified: 2026-09-18T13:28:28.567

Link: CVE-2026-20360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:31:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor