Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-76409 are related to improper limitation of a pathname issues that are grouped under the Common Weakness Enumeration (CWE) CWE-22.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted file access via path traversal
Action: Patch
AI Analysis

Impact

The flaw arises from improper limitation of a pathname in Cisco Nexus Dashboard Software. This weakness, classified as CWE-22, permits an attacker to influence path resolution and potentially read or write arbitrary files on the host system. The advisory indicates that any file outside the intended scope could be accessed, thereby exposing sensitive configuration data or enabling further compromise of the device. Based on the description, it is inferred that the vulnerability could be leveraged for both confidentiality and integrity violations.

Affected Systems

Cisco Nexus Dashboard, a software component used to manage and monitor Cisco Nexus hardware. Specific affected releases are not enumerated in the advisory, so all installations of the Nexus Dashboard running prior to the September 2026 hardening release are subject to the flaw.

Risk and Exploitability

The CVSS score of 8.8 reflects a high severity potential consequence. The EPSS score of less than 1% suggests that exploitation observed in the wild is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. The advisory does not specify authentication or privilege requirements, so the likely attack vector is any interface that accepts user-supplied pathnames; based on the description, it is inferred that an attacker may not need elevated privileges to exploit the flaw. Successful exploitation could allow arbitrary file reads or writes, posing a serious risk to system integrity and confidentiality.

Generated by OpenCVE AI on September 18, 2026 at 01:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Cisco Nexus Dashboard Software Hardening Release September 2026, which includes the fix for the pathname limitation issue.
  • Configure the Nexus Dashboard process to run with the least privileges necessary, restricting filesystem access to critical files and directories.
  • Limit interfaces that accept user-supplied pathnames to authenticated and authorized users only, reducing the attack surface.
  • Monitor system logs for unusual file access patterns that may indicate exploitation attempts.

Generated by OpenCVE AI on September 18, 2026 at 01:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco nexus Dashboard
Vendors & Products Cisco
Cisco nexus Dashboard

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76409 are related to improper limitation of a pathname issues that are grouped under the Common Weakness Enumeration (CWE) CWE-22.
Title Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Limitation of a Pathname
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cisco Nexus Dashboard
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T13:41:15.897Z

Reserved: 2026-08-19T12:02:03.632Z

Link: CVE-2026-76409

cve-icon Vulnrichment

Updated: 2026-09-18T13:32:35.203Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:13.597

Modified: 2026-09-18T14:18:39.357

Link: CVE-2026-76409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')