CVE-2026-20046Disclosure(cisco / ios_xr)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cisco ios_xr systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerability is due to incorrect mapping of a command to task groups within the source code. An attacker with a low-privileged account could exploit this vulnerability by using the CLI command to bypass the task group–based checks. A successful exploit could allow the attacker to elevate privileges and perform actions on an affected device without authorization checks.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-264

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ios_xr
  • ios_xrv_9000

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-03-11); latest day: 1
  • 11 total mentions across 4 days

Affected systems

Vendors
Products
ios_xrios_xrv_9000

1 version affected across 2 products

Deep dive

Activity timeline11 mentions / 4d
01234Mentions · 2026-03-11: 4Mentions · 2026-03-12: 4Mentions · 2026-03-13: 2Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-12: 3Technical Details · 2026-03-11: 3Technical Details · 2026-03-12: 3Technical Details · 2026-03-13: 203-1103-1203-1303-18
Signal classification3 categories
Disclosure
763.6%
Patch
327.3%
General
19.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-114
Disclosure4
2026-03-124
Disclosure1Patch3
2026-03-132
Disclosure2
2026-03-181
General1
Full discourse11 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Cisco ❗ CVE-2026-20074 ❗ CVE-2026-20046 ❗ CVE-2026-20040 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cisco-11/ https://t.co/dWJ8IQdthG

    Post summary

    The tweet simply lists three Cisco product CVEs and links to external sources for more information, offering no technical, exploit, or mitigation details.

    01010160
    6.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Cisco patched 4 vulnerabilities in it's IOS XR software. The two most critical flaws (#CVE-2026-20040, #CVE-2026-20046 ; CVSSv3.1 8.8 ) could allow an authenticated local attacker to execute arbitrary commands as root. #Patch #Patch #Patch

    Post summary

    Cisco has released patches for two critical IOS XR vulnerabilities (CVE‑2026‑20040 and CVE‑2026‑20046) that could allow local authenticated attackers to run arbitrary commands as root. The CVSSv3.1 score is 8.8.

    01001320
    7.2K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Cisco patches critical privilege escalation flaws (CVE-2026-20040, CVE-2026-20046) in IOS XR software that allow local attackers to gain full root access. #Cisco #CVE #CyberSecurity #NetworkSecurity #PatchAlert #InfoSec https://securityonline.info/root-access-via-cli-cisco-patches-critical-ios-xr-privilege-escalation-flaws/ https://t.co/GexEiGGl59

    Post summary

    Cisco issued patches for two critical local privilege escalation CVEs (CVE-2026-20040 and CVE-2026-20046) in IOS XR, allowing attackers to gain full root access; no active exploitation or PoC evidence is reported.

    01010321
    10.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-20046 A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and ga… https://www.cve.org/CVERecord?id=CVE-2026-20046 ----- Traducción: CVE-2026-20046 Una… http://infoflow.cloud`

    Post summary

    The tweet discloses CVE‑2026‑20046, stating it allows an authenticated, local attacker to elevate privileges in Cisco IOS XR Software, but provides no evidence of exploitation, PoC, or patch details.

    0000039
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20046 A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and ga… https://www.cve.org/CVERecord?id=CVE-2026-20046

    Post summary

    CVE‑2026‑20046 is a privileged‑escalation vulnerability in Cisco IOS XR that allows an authenticated local attacker to exploit a CLI task‑group assignment issue.

    00000205
    56.7K followersView on X
  • Jeff Hall - PCI Guru - #StandWithUkraine@jbhall56
    Patch

    The most severe of these issues are CVE-2026-20040 and CVE-2026-20046 (CVSS score of 8.8), two bugs that could be exploited to execute arbitrary commands as root or gain administrative control of a device. https://www.securityweek.com/cisco-patches-high-severity-ios-xr-vulnerabilities-2/

    Post summary

    The text reports that Cisco has patched high‑severity IOS XR vulnerabilities CVE‑2026‑20040 and CVE‑2026‑20046, which allow root command execution and administrative control, with a CVSS score of 8.8.

    0000044
    903 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-20046 - Cisco - Cisco IOS XR Software - https://www.redpacketsecurity.com/cve-alert-cve-2026-20046-cisco-cisco-ios-xr-software/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-20046 #cisco #cisco-ios-xr-software

    Post summary

    A CVE alert for CVE‑2026‑20046 related to Cisco IOS XR Software was posted, linking to a RedPacketSecurity page but offering no further technical or remediation details.

    0000079
    3.5K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Cisco IOS XR (CVE-2026-20046) https://vuldb.com/?id.350482

    Post summary

    A new vulnerability CVE-2026-20046 in Cisco IOS XR with increased severity was announced, referencing a Vuldb page but lacking detailed technical or mitigation information.

    0000089
    2.1K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-20046: HIGH] Vulnerability in Cisco IOS XR Software allows local attacker to gain administrative control by exploiting task group assignment flaw. Attackers could bypass checks to elevate privileges.#cve,CVE-2026-20046,#cybersecurity https://cvefind.com/CVE-2026-20046

    Post summary

    The post reports a high-severity local privilege escalation vulnerability (CVE-2026-20046) in Cisco IOS XR that could let an attacker gain administrative control by exploiting a task group assignment flaw.

    0000045
    602 followersView on X
  • dbugs@ptdbugs
    Disclosure

    Cisco IOS XR Software CLI Privilege Escalation Vulnerability CVE: CVE-2026-20046 Vendor: Cisco Product: Cisco IOS XR Software CVSS: 8.8 Credits: n/a Description: A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerability is due to incorrect mapping of a command to task groups within the source code. An attacker with a low-privileged account could exploit this vulnerability by using the CLI command to bypass the task group–based checks. A successful exploit could allow the attacker to elevate privileges and perform actions on an affected device without authorization checks. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-20046 • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-privesc-bF8D5U4W #dbugs_vuln

    Post summary

    Cisco disclosed a privilege‑escalation flaw (CVE‑2026‑20046) in IOS XR, noting a CVSS of 8.8 and source‑code mapping error, but no exploitation evidence or PoC details were provided.

    0000065
    579 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-20046 - High A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative co... https://www.thehackerwire.com/vulnerability/CVE-2026-20046/ https://t.co/WB0OPZJKiN

    Post summary

    The tweet announces CVE‑2026‑20046, a high‑severity privilege‑elevation flaw in Cisco IOS XR software, and links to an article with more details. No exploits, patches, or evidence of active use are provided.

    0000036
    134 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSciscoios_xr---
HWciscoios_xrv_9000---

Explore more