CVE-2026-20113
published 2026-03-25CVE-2026-20113: A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote…
PriorityP434medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.29%
20.9th percentile
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to arbitrarily inject log entries, manipulate the structure of log files, or obscure legitimate log events.
Affected
228 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco IOS XE up to 17.18.1x crlf injection (cisco-sa-iox-crlf-NvgKTKJZ / EUVD-2026-15443)
vuldb·2026-04-25·CVSS 5.3
CVE-2026-20113 [MEDIUM] Cisco IOS XE up to 17.18.1x crlf injection (cisco-sa-iox-crlf-NvgKTKJZ / EUVD-2026-15443)
A vulnerability described as problematic has been identified in Cisco IOS XE. Affected is an unknown function of the component Application Hosting Environment Management Interface. Executing a manipulation can lead to crlf injection.
This vulnerability is handled as CVE-2026-20113. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-c9q8-fg52-4crv: A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticate
ghsa_unreviewed·2026-03-25
CVE-2026-20113 [MEDIUM] CWE-93 GHSA-c9q8-fg52-4crv: A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticate
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to arbitrarily inject log entries, manipulate the structure of log files, or obscure legitimate log events.
Cisco
Cisco IOx Application Hosting Environment Carriage Return Line Feed Injection Vulnerability
vendor_cisco·2026-03-25·CVSS 5.3
CVE-2026-20113 [MEDIUM] CWE-93 Cisco IOx Application Hosting Environment Carriage Return Line Feed Injection Vulnerability
Cisco IOx Application Hosting Environment Carriage Return Line Feed Injection Vulnerability
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to arbitrarily inject log entries, manipulate the structure of log files, or obscure legitimate log events.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory
Cisco
Cisco IOx Application Hosting Environment Carriage Return Line Feed Injection Vulnerability
vendor_cisco·CVSS 3.1
CVE-2026-20113 Cisco IOx Application Hosting Environment Carriage Return Line Feed Injection Vulnerability
CVE-2026-20113: Cisco IOx Application Hosting Environment Carriage Return Line Feed Injection Vulnerability
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to arbitrarily inject log entries, manipulate the structure of log files, or obscure legitimate log events. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-93, CWE-93
Bug IDs: CSCwq6
No detection rules found.
No public exploits indexed.
2026-03-25
Published