CVE-2026-76409

Cisco · Nexus Dashboard

Cisco Nexus Dashboard is affected by a path traversal vulnerability (CWE-22) that could allow an authenticated attacker to access or manipulate restricted files on the system.

Executive summary

A path traversal vulnerability in Cisco Nexus Dashboard allows authenticated remote attackers to compromise system files, posing a high risk to infrastructure integrity.

Vulnerability

This vulnerability is a path traversal flaw (CWE-22) where improper limitation of a pathname allows an authenticated user with low privileges to access files outside of the intended directory.

Business impact

The CVSS score of 8.8 indicates a high-severity risk, as the vulnerability facilitates unauthorized access to sensitive system files. Successful exploitation could lead to the exposure of configuration data, credentials, or other critical information, potentially enabling full system compromise and significant operational disruption.

Remediation

Immediate Action: Consult the official Cisco security advisory for the specific software hardening release that addresses these vulnerabilities.

Proactive Monitoring: Monitor system logs for unusual file access patterns or attempts to navigate directory structures using path traversal sequences like dot-dot-slash.

Compensating Controls: Ensure that the Nexus Dashboard is deployed within a protected network segment and restrict access to authorized administrative accounts only to minimize the potential attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score, organizations should prioritize reviewing their Cisco Nexus Dashboard deployments against the affected versions listed. Administrators must apply the vendor-provided hardening updates as soon as they are available to mitigate the risk of unauthorized file access and potential system-wide compromise.

More Cisco CVEs all →

History

  1. Collected by CVE Brief via github
  2. Held for re-check analysis graded thin
  3. Analyst report written
  4. Held for re-check analysis graded thin

Sources