CVE-2026-20037Disclosure

LOWCVSS 4.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authenticated, local attacker with read-only privileges to modify files and perform unauthorized actions on an affected system.   This vulnerability exists because unnecessary privileges are given to the user. An attacker could exploit this vulnerability by authenticating to a device as a read-only user and connecting to the NX-OS CLI. A successful exploit could allow the attacker to create or overwrite files in the file system or perform limited privileged actions on an affected device.   

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-26)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-25: 1Mentions · 2026-02-26: 2Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 202-2502-26
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-251
Disclosure1
2026-02-262
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-20037 A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authenticated, local attacker with read-only privileges to modify files… https://www.cve.org/CVERecord?id=CVE-2026-20037 ----- Traducción: CVE-2026-20037 Una… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑20037, describing a local privilege escalation vulnerability in Cisco UCS Manager’s NX‑OS CLI that could allow read‑only users to modify files, but provides no PoC, exploit, or patch details.

    0000039
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20037 A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authenticated, local attacker with read-only privileges to modify files… https://www.cve.org/CVERecord?id=CVE-2026-20037

    Post summary

    The CVE‑2026‑20037 vulnerability in Cisco UCS Manager Software allows a local authenticated user with read‑only privileges to modify files through NX‑OS CLI privilege levels.

    00000901
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-20037 Local Privilege Escalation in Cisco UCS Manager Software via NX-OS CLI https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20037

    Post summary

    A local privilege escalation vulnerability (CVE‑2026‑20037) in Cisco UCS Manager via NX‑OS CLI has been disclosed, but no PoC, exploit, patch, or active exploitation details are provided.

    0000039
    4.0K followersView on X

Explore more