PT-2026-21940 · Cisco · Cisco Application Policy Infrastructure Controller

Ash Khamas

·

Published

2026-02-25

·

Updated

2026-02-28

·

CVE-2026-20107

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Application Policy Infrastructure Controller (APIC) (affected versions not specified)
Description A flaw exists in the Object Model CLI component that may allow an authenticated, local attacker to trigger an unexpected reload of the device, leading to a denial of service (DoS). The issue stems from inadequate input validation. An attacker can exploit this by submitting specially crafted commands through the CLI prompt. The attacker must possess valid user credentials and a role with CLI access to succeed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Weakness Enumeration

Related Identifiers

CVE-2026-20107

Affected Products

Cisco Application Policy Infrastructure Controller