CVE-2026-20267

Published Aug 5, 2026

Last updated 4 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-20267 is an improper access control vulnerability (CWE-284) affecting Cisco IOS XE Software. This flaw was identified internally by Cisco's engineering team during a thorough security review, which leveraged both existing testing methodologies and advanced AI models. The vulnerability could potentially lead to authentication or authorization bypass within affected Cisco IOS XE Software, which runs in autonomous or controller mode. It is part of a series of internally discovered issues addressed in recent software hardening releases for various Cisco IOS XE Software versions, including release trains 17.9, 17.12, 17.15, 17.18, and 26.1.

Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.
Source
psirt@cisco.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9
Impact score
6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@cisco.com
CWE-284

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1