CVE-2026-20042
published 2026-04-01CVE-2026-20042: A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or…
PriorityP347medium6.5CVSS 3.1
AVNACLPRHUINSUCHIHAN
EPSS
0.29%
21.2th percentile
A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information.
This vulnerability exists because authentication details are included in the encrypted backup files. An attacker with a valid backup file and encryption password from an affected device could decrypt the backup file. The attacker could then use the authentication details in the backup file to access internal-only APIs on the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
| cisco | cisco_nexus_dashboard | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
vendor_cisco3.1
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Nexus Dashboard Configuration Backup REST API Unauthorized Access Vulnerability
vendor_cisco·CVSS 3.1
CVE-2026-20042 Cisco Nexus Dashboard Configuration Backup REST API Unauthorized Access Vulnerability
CVE-2026-20042: Cisco Nexus Dashboard Configuration Backup REST API Unauthorized Access Vulnerability
A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability exists because authentication
CVSS: 3.1
CWE: CWE-295, CWE-295
Bug IDs: CSCwq66302
GHSA
GHSA-4jcc-jgc6-vpm7: A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Ful
ghsa_unreviewed·2026-04-01
CVE-2026-20042 [MEDIUM] CWE-295 GHSA-4jcc-jgc6-vpm7: A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Ful
A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information.
This vulnerability exists because authentication details are included in the encrypted backup files. An attacker with a valid backup file and encryption password from an affected device could decrypt the backup file. The attacker could then use the authentication details in the backup file to access internal-only APIs on the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-01
Published