VDB

CVE-2026-20191

CVE-2026-20191 PUBLISHED CVSS 7.5 HIGH

Reported by cisco · Published July 1, 2026

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
CiscoCisco Catalyst Center2.3.7.0-VA, 2.3.7.5-VA, 2.3.7.6-VA
CiscoCisco Catalyst Center2.3.7.0-VA, 2.3.7.5-VA, 2.3.7.6-VA

Timeline

  • Jul 1, 2026 CVE Published
  • Jul 1, 2026 CVE Updated
  • Jul 2, 2026 EPSS Score
  • Jul 2, 2026 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›