Impact
This vulnerability allows an attacker to inject malicious SQL statements through the Cisco Nexus Dashboard, potentially enabling unauthorized access to, modification of, or deletion from the underlying database. The weakness is classified as CWE‑89, implying that user-supplied input can be interpreted as database commands. Compromise of the database may expose configuration data, privileges, or any other content stored within.
Affected Systems
The affected system is Cisco Nexus Dashboard software, as identified by Cisco. The vulnerability applies to any installation of this product that has not yet received Cisco’s September 2026 hardening release.
Risk and Exploitability
The CVSS score of 8.8 categorises the issue as high severity, while the EPSS score of less than 1 % indicates a very low likelihood of exploitation at the time of this analysis. It is not listed in CISA’s KEV catalog. The likely attack vector is through exposed management interfaces or API endpoints that accept user input, and the mitigation requires patching the software or ensuring input parameters are properly sanitized. The attack would require access to a vulnerable endpoint and the ability to send crafted HTTP requests, but no authentication escalation is indicated by the provided information.
OpenCVE Enrichment