VDB

CVE-2026-20032

CVE-2026-20032 PUBLISHED CVSS 4.4 MEDIUM

Reported by cisco · Published October 7, 2026

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by manipulating specific functions within the Python interpreter. A successful exploit could allow an attacker to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user.

Risk Scores

CVSS 3.1
4.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
CiscoCisco NX-OS Software8.2(5), 7.3(5)D1(1), 8.4(2)
CiscoCisco NX-OS Software8.2(5), 7.3(5)D1(1), 8.4(2)

Timeline

  • Oct 7, 2026 Coalition ESS Score
  • Oct 7, 2026 CVE Published
  • Oct 7, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›