Impact
The vulnerability identified as CVE‑2026‑76472 is an Improper Neutralization of Special Elements flaw, classified under CWE‑74. This weakness allows injected malicious input to bypass sanitization checks. Based on the description, it is inferred that such input could lead to command, script, or configuration injection, potentially compromising confidentiality, integrity, or availability of the device or network. The CVE does not explicitly state that it results in remote code execution.
Affected Systems
Affected systems include Cisco Campus Gateway Software, Cisco Meraki MR Wireless Access Points Software, Cisco Meraki MV Firmware, and Cisco Meraki MX Firmware. No specific version numbers are listed in the advisory, so all current iterations of these products should be considered potentially vulnerable until patched.
Risk and Exploitability
The CVSS score of 8.8 demonstrates high severity. The EPSS score is not available, so the current exploitation probability is unclear, and the lack of known public exploits and absence from CISA’s KEV inventory suggest no widespread active attacks. Nonetheless, given the nature of the flaw and the high CVSS, threat actors could target these devices via remote management interfaces or APIs, exploiting the weakness if the device is exposed to untrusted input paths. (The likely attack vector is inferred.)
OpenCVE Enrichment