CVE-2026-20279

Published Sep 2, 2026

Last updated 2 days ago

CVSS critical 9.8
Cisco IOS XR Software

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-20279 identifies a set of improper access control vulnerabilities within Cisco IOS XR Software, categorized under Common Weakness Enumeration (CWE) CWE-284. These issues were discovered internally by Cisco's engineering team during a comprehensive security review. The vulnerabilities encompassed by CVE-2026-20279 include missing authentication for critical functions, improper certificate validation, and incorrect authorization. Exploitation of these flaws could allow a remote attacker to bypass existing authentication or authorization mechanisms, thereby gaining unauthorized access to critical functionalities or protected resources.

Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20279 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
Source
psirt@cisco.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@cisco.com
CWE-284

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

35