CVE Database
/

CVE-2026-20041

Back to search

CVE-2026-20041

Published: Apr 1, 2026

Modified: Apr 1, 2026

PUBLISHED

CVSS v3.1

6.1

MEDIUM

Description

A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by persuading an authenticated user of the device management interface to click a crafted link. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device to an attacker-controlled server. The attacker could then execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.

VendorProductVersions

Cisco

Cisco Nexus Dashboard

affected
1.1(3e)
affected
1.1(3c)
affected
1.1(3d)
affected
1.1(0d)
affected
1.1(2i)

+35 more versions

Cisco

Cisco Nexus Dashboard Insights

affected
2.2.2.125
affected
2.2.2.126
affected
5.0.1.150
affected
5.0.1.154
affected
5.1.0.131

+10 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now