CVE-2026-20040Disclosure(cisco / ios_xr)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cisco ios_xr systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker with a low-privileged account could exploit this vulnerability by using crafted commands at the prompt. A successful exploit could allow the attacker to elevate privileges to root and execute arbitrary commands on the underlying operating system.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ios_xr

Threat summary

  • Patch or workaround signal is available
  • 13 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 4 mentions (2026-03-11); latest day: 1
  • 13 total mentions across 5 days

Affected systems

Vendors
Products
ios_xr

Deep dive

Activity timeline13 mentions / 5d
01234Mentions · 2026-03-11: 4Mentions · 2026-03-12: 4Mentions · 2026-03-13: 3Mentions · 2026-03-18: 1Mentions · 2026-03-19: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-12: 3Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-11: 2Technical Details · 2026-03-12: 3Technical Details · 2026-03-13: 3Technical Details · 2026-03-19: 103-1103-1203-1303-1803-19
Signal classification3 categories
Disclosure
538.5%
Patch
538.5%
General
323.1%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-114
Disclosure3Patch1
2026-03-124
General1Patch3
2026-03-133
Disclosure1General1Patch1
2026-03-181
General1
2026-03-191
Disclosure1
Full discourse13 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Cisco ❗ CVE-2026-20074 ❗ CVE-2026-20046 ❗ CVE-2026-20040 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cisco-11/ https://t.co/dWJ8IQdthG

    Post summary

    A brief announcement listing three Cisco CVE identifiers with links for further details.

    01010160
    6.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Cisco patched 4 vulnerabilities in it's IOS XR software. The two most critical flaws (#CVE-2026-20040, #CVE-2026-20046 ; CVSSv3.1 8.8 ) could allow an authenticated local attacker to execute arbitrary commands as root. #Patch #Patch #Patch

    Post summary

    Cisco has issued patches for four IOS XR vulnerabilities, including CVE‑2026‑20040 and CVE‑2026‑20046, which could allow authenticated local attackers to run arbitrary commands as root.

    01001320
    7.2K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Cisco patches critical privilege escalation flaws (CVE-2026-20040, CVE-2026-20046) in IOS XR software that allow local attackers to gain full root access. #Cisco #CVE #CyberSecurity #NetworkSecurity #PatchAlert #InfoSec https://securityonline.info/root-access-via-cli-cisco-patches-critical-ios-xr-privilege-escalation-flaws/ https://t.co/GexEiGGl59

    Post summary

    The tweet announces that Cisco has released patches for two critical privilege‑escalation vulnerabilities (CVE‑2026‑20040 and CVE‑2026‑20046) in IOS XR that allow local attackers to gain full root access.

    01010321
    10.6K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Cisco IOS XR の脆弱性 CVE-2026-20040/20046 が FIX:root でのコマンド実行と管理者権限の取得 https://iototsecnews.jp/2026/03/12/cisco-ios-xr-software-vulnerability-allow-attacker-to-execute-commands-as-root/ 大規模ネットワーク向け OS である Cisco IOS XR Software において、root権限の奪取や管理者制御の回避を許す2件の深刻な脆弱性が発見されました。これらの問題の原因は、CLI コマンド実行時におけるユーザー入力値の検証不備と、コマンドと権限グループの紐付けミスという設計上の欠陥にあります。 特に警戒すべき CVE-2026-20040 は、特定の CLI コマンドに不正な引数を注入することで、OS の最高権限である root としての任意のコマンド実行に至るものです。 もう一方のCVE-2026-20046は、仮想ルーターであるIOS XRv 9000 に特有の問題であり、タスクグループの定義ミスを突く低権限ユーザーに、管理用コマンドの認可チェックの回避を許すものです。ご利用のチームは、ご注意ください。 #Cisco #CVE202620040 #CVE202620046 #IOSXR #Vulnerability

    Post summary

    The article announces two critical Cisco IOS XR vulnerabilities that enable root command execution and privilege escalation, detailing how the flaws arise but providing no PoC, exploit code, or evidence of active exploitation.

    01000187
    484 followersView on X
  • Machina Record@MachinaRecord
    Patch

    🩹シスコ、IOS XRソフトウェアにおける深刻度Highの脆弱性4件にパッチ(CVE-2026-20040、CVE-2026-20046他) ⚠️Veeam、VBRにおけるCriticalなRCE脆弱性などについて警告(CVE-2026-21666、CVE-2026-21667他) 〜サイバーアラート3月13日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/44562/

    Post summary

    The post announces Cisco IOS XR patches for four high‑severity CVEs and warns about critical RCE vulnerabilities in Veeam VBR, providing CVE IDs and severity but no exploitation details.

    00010219
    1.3K followersView on X
  • dbugs@ptdbugs
    Disclosure

    Cisco IOS XR Software CLI Privilege Escalation Vulnerability CVE: CVE-2026-20040 Vendor: Cisco Product: Cisco IOS XR Software CVSS: 8.8 Credits: n/a Description: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker with a low-privileged account could exploit this vulnerability by using crafted commands at the prompt. A successful exploit could allow the attacker to elevate privileges to root and execute arbitrary commands on the underlying operating system. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-20040 • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-privesc-bF8D5U4W #dbugs_vuln

    Post summary

    The advisory discloses a privilege‑escalation flaw in Cisco IOS XR CLI (CVE‑2026‑20040) that can let local authenticated users gain root access. No PoC, exploit, or patch information is provided.

    0010097
    579 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-20040 A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating sys… https://www.cve.org/CVERecord?id=CVE-2026-20040 ----- Traducción: CVE-2026-20040 Una… http://infoflow.cloud`

    Post summary

    The text only reports the CVE number and a brief description of its impact, without details on PoC, exploitation, or remediation.

    0000048
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20040 A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating sys… https://www.cve.org/CVERecord?id=CVE-2026-20040

    Post summary

    The passage announces CVE-2026-20040 as a local authenticated CLI vulnerability in Cisco IOS XR that permits root-level command execution, but it offers no PoC, exploit, or mitigation details.

    00000366
    56.7K followersView on X
  • Jeff Hall - PCI Guru - #StandWithUkraine@jbhall56
    Patch

    The most severe of these issues are CVE-2026-20040 and CVE-2026-20046 (CVSS score of 8.8), two bugs that could be exploited to execute arbitrary commands as root or gain administrative control of a device. https://www.securityweek.com/cisco-patches-high-severity-ios-xr-vulnerabilities-2/

    Post summary

    Cisco has released patches for two high‑severity CVEs that allow arbitrary command execution or administrative takeover, as indicated by the referenced article.

    0000044
    903 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-20040 - Cisco - Cisco IOS XR Software - https://www.redpacketsecurity.com/cve-alert-cve-2026-20040-cisco-cisco-ios-xr-software/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-20040 #cisco #cisco-ios-xr-software

    Post summary

    The tweet shares a link to a CVE alert for Cisco IOS XR software but provides no additional technical details, PoC, exploit, or active exploitation information.

    0000093
    3.5K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Cisco IOS XR (CVE-2026-20040) https://vuldb.com/?id.350471

    Post summary

    Announcement of a new elevated‑critical vulnerability (CVE-2026-20040) affecting Cisco IOS XR, with no additional details or mitigation information provided.

    0000089
    2.1K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-20040 - High A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device... https://www.thehackerwire.com/vulnerability/CVE-2026-20040/ https://t.co/StSCUDVOzH

    Post summary

    The text announces a high‑severity vulnerability (CVE‑2026‑20040) in Cisco IOS XR CLI that allows an authenticated local attacker to execute commands as root, but provides no further technical detail or evidence of exploitation.

    0000049
    134 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-20040: HIGH] Cisco IOS XR Software vulnerability allows local attackers to run arbitrary commands as root due to insufficient validation of user arguments.Upgrade to patched version ASAP.#cve,CVE-2026-20040,#cybersecurity https://cvefind.com/CVE-2026-20040

    Post summary

    The tweet warns of a high‑severity CVE-2026-20040 in Cisco IOS XR that permits local root command execution and urges users to upgrade to the patched version.

    0000052
    602 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSciscoios_xr---

Explore more