CVE-2026-20168Disclosure(cisco / iot_field_network_director)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerability is due to insufficient file access checks. An attacker could exploit this vulnerability by submitting crafted input in the web-based management interface. A successful exploit could allow the attacker to read files that they are not authorized to access.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-388

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • iot_field_network_director

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-06); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
iot_field_network_director

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-06: 2Mentions · 2026-05-07: 1Technical Details · 2026-05-06: 205-0605-07
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-062
Disclosure2
2026-05-071
Disclosure1
Full discourse3 posts
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-20167 CVE-2026-20168 CVE-2026-20169 Cisco IoT Field Network Director Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iot-fnd-dos-n8N26Q4u

    Post summary

    The notice lists three CVEs pertaining to Cisco IoT Field Network Director and provides a link to a Cisco security advisory detailing these vulnerabilities.

    00010442
    6.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-20168 A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retriev… https://www.cve.org/CVERecord?id=CVE-2026-20168 ----- Traducción: CVE-2026-20168 Una… http://infoflow.cloud`

    Post summary

    The brief text announces CVE-2026-20168, a Cisco IoT Field Network Director vulnerability that allows low‑privilege authenticated remote data retrieval via the web interface, without providing PoC, exploit, or patch details.

    0000036
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20168 A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retriev… https://www.cve.org/CVERecord?id=CVE-2026-20168

    Post summary

    The text presents a brief disclosure of CVE-2026-20168, noting its impact on Cisco IoT Field Network Director's web interface and indicating that an authenticated remote attacker with low privileges could exploit it. No PoC, exploit, patch, or active‑exploitation information is provided.

    00000123
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoiot_field_network_director---

Explore more