PT-2026-29550 · Cisco · Cisco Nexus Dashboard

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-20042

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Cisco Nexus Dashboard (affected versions not specified)
Description A flaw in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker with the encryption password and access to backup files to access sensitive information. The issue stems from the inclusion of authentication details within the encrypted backup files. An attacker could decrypt a backup file and leverage the contained authentication details to access internal APIs, potentially leading to arbitrary command execution on the operating system as a root user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2026-04791
CVE-2026-20042

Affected Products

Cisco Nexus Dashboard