VDB

GCVE-110-NCSC-2026-406

GCVE-110-NCSC-2026-406
Advisory PublishedCVSS 8.6/10
Vulnetix · Advisory published October 8, 2026
A vulnerability in Cisco NX-OS Software's Python interpreter allows an authenticated local attacker with low privileges to escape the Python sandbox and execute arbitrary commands on the underlying operating system due to insufficient input validation.

Weaknesses (CWE)

CWE-653Improper Isolation or CompartmentalizationCWE-770Allocation of Resources Without Limits or ThrottlingCWE-125Out-of-bounds ReadCWE-787Out-of-bounds WriteCWE-122Heap-based Buffer Overflow

Risk Scores

CVSS 3.1
8.6/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Affected Products

VendorProductVersionsPlatforms
Ciscovers:unknown/*——

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

3,450 records in the GCVE database · Updated October 8, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›