CVE-2026-20174Patch(cisco / nexus_dashboard)

LOWCVSS 4.9 · MEDIUM

Signal is active with 9 mentions in latest observed window

Immediate actions

  • Patch cisco nexus_dashboard systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the metadata update file. An attacker could exploit this vulnerability by crafting a metadata update file and manually uploading it to an affected device. A successful exploit could allow the attacker to write arbitrary files to the underlying operating system as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials. Note: Manual uploading of metadata files is typical for Air-Gap environments but not for Cisco Intersight Cloud connected devices. However, the manual upload option exists for both deployments.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nexus_dashboard
  • nexus_dashboard_insights

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 9 signals
  • Disclosure: 4 classified signals
  • 9 total mentions across 1 day

Affected systems

Vendors
Products
nexus_dashboardnexus_dashboard_insights

Deep dive

Activity timeline9 mentions / 1d
02579Mentions · 2026-04-01: 9Patch / Workaround · 2026-04-01: 9Technical Details · 2026-04-01: 904-01
Signal classification2 categories
Patch
555.6%
Disclosure
444.4%
Referenced assets5 URLs
Full discourse9 posts
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability 📅 **Timeline:** Disclosure: 2026-04-01, Patch: 2026-04-01 🆔 **CVE-2026-20174** | 📊 CVSS: 4.9 (Medium 🟡) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Cisco Nexus Dashboard Insights 6.5 and earlier, Nexus Dashboard Release 3.1/3.2/4.1 (migrate to fixed releases), Nexus Dashboard Release 4.2+ 🔧 **Fixed Versions:** Nexus Dashboard Release 4.2+, Fixed releases per Cisco advisory 🫨 **Attack Vectors:** - Authenticated (administrative) remote upload of crafted metadata update file - Manual upload vector typical in air-gapped deployments (manual upload option exists for cloud-connected devices) 📝 **Summary:** An authenticated attacker with administrative access can upload a crafted metadata file that bypasses validation and writes arbitrary files to the OS as root, enabling privilege escalation and potential full system compromise. The manual upload option increases exposure in air‑gapped and some cloud-connected deployments—apply Cisco fixes immediately. 📈 **Impact Scope:** Arbitrary file writes as root leading to potential full system compromise of affected Nexus Dashboard Insights instances; risk is higher where manual metadata upload is enabled. 🛡️ **Recommended Actions:** - Upgrade affected systems to the fixed Nexus Dashboard / Nexus Dashboard Insights releases documented by Cisco immediately - Disable or tightly control manual metadata uploads and restrict to isolated maintenance windows - Enforce least-privilege for administrative accounts and rotate credentials - Monitor upload and system logs for suspicious metadata uploads and unexpected file writes - Test and validate upgrades in staging and contact Cisco TAC for assistance 🪢 **Related Resources:** - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndi-afw-rJuRC5dZ - https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws40848 🏷 **Tags:** #Cybersecurity #Cisco #NexusDashboardInsights

    Post summary

    Cisco has disclosed an arbitrary file write vulnerability (CVE-2026-20174) in Nexus Dashboard Insights, allowing authenticated administrators to upload crafted metadata files that write arbitrary files as root. A patch was issued on 2026‑04‑01, and Cisco recommends immediate upgrade and disabling of manual upload options.

    0000055
    276 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability 📅 **Timeline:** Disclosure: 2026-04-01; Patch: Not Available 🆔 **CVE-2026-20174** | 📊 CVSS: 4.9 (Medium 🟡) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Cisco Nexus Dashboard Insights 6.5 and earlier, Cisco Nexus Dashboard unified images prior to fixed release 🔧 **Fixed Versions:** Upgrade to the fixed Nexus Dashboard release as per Cisco advisory 🫨 **Attack Vectors:** - Authenticated administrative credentials required - Manual metadata update file upload (common in air-gapped deployments) 📝 **Summary:** A flaw in the metadata update feature allows an authenticated admin to upload a crafted metadata file that can write arbitrary files as root, enabling data tampering, potential code execution, or full system compromise. Requires valid admin credentials; the manual upload vector heightens risk for air-gapped deployments. Cisco reports no known public exploitation at disclosure. 📈 **Impact Scope:** Arbitrary file write as root on affected Nexus Dashboard Insights instances; potential for code execution and full compromise. Requires valid admin credentials; manual upload vector increases risk for air-gapped deployments. No known public exploitation as of disclosure. 🛡️ **Recommended Actions:** - Upgrade affected systems to Cisco's fixed Nexus Dashboard release immediately - Restrict administrative access and enforce strong credential controls (MFA, least privilege) - Audit and monitor metadata uploads and system integrity logs - Isolate management interfaces and apply network segmentation 🪢 **Related Resources:** - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndi-afw-rJuRC5dZ - https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws40848 🏷 **Tags:** #Cybersecurity #Cisco #NexusDashboard

    Post summary

    The post announces the discovery of CVE‑2026‑20174, detailing its technical impact, affected versions, and recommended patching steps, with no evidence of active exploitation or verification of a false positive.

    0000058
    276 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability 📅 **Timeline:** Disclosure: Not Available, Patch: Not Available 🆔 **CVE-2026-20174** | 📊 CVSS: 4.9 (Medium 🟡) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Nexus Dashboard Insights 6.5 and earlier, Releases prior to fixed releases (see advisory) 🔧 **Fixed Versions:** Fixed release per Cisco advisory, Release 4.2 and later 🫨 **Attack Vectors:** - Authenticated (administrative) remote metadata file upload - Manual metadata file upload in air-gapped or cloud-connected deployments leading to arbitrary file write 📝 **Summary:** An authenticated admin can upload a crafted metadata file that results in arbitrary files being written as root, enabling privilege escalation and potential full system compromise on affected Nexus Dashboard Insights instances. This impacts both air-gapped and cloud-connected deployments where metadata upload is permitted. 📈 **Impact Scope:** Arbitrary root file writes leading to privilege escalation and potential full system compromise; noted for Nexus Dashboard Insights 6.5 and earlier and other pre-fixed releases. 🛡️ **Recommended Actions:** - Upgrade to the fixed Nexus Dashboard release indicated in the Cisco advisory immediately - If you cannot patch, disable or tightly restrict metadata file upload and limit admin interface access to trusted networks - Rotate and audit admin credentials/keys and enforce least privilege - Isolate affected systems and monitor for suspicious root-level file changes 🪢 **Related Resources:** - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndi-afw-rJuRC5dZ - https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws40848 🏷 **Tags:** #Cybersecurity #Cisco #NexusDashboardInsights

    Post summary

    The post details an authenticated administrator privilege escalation vulnerability in Cisco Nexus Dashboard Insights, noting arbitrary root file writes, and recommends patching or disabling the metadata upload interface to mitigate the risk.

    0000058
    276 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability (consolidated) 🆔 **CVE-2026-20174** | 📊 CVSS: 4.9 (Medium 🟡) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Cisco Nexus Dashboard Insights - 6.5 and earlier, Cisco Nexus Dashboard (unified image) releases that include Nexus Dashboard Insights prior to fixed releases 🔧 **Fixed Versions:** Fixed unified Nexus Dashboard image (see advisory), Cisco Nexus Dashboard Release 4.2 🫨 **Attack Vectors:** - Network access (requires authenticated administrative credentials) - Manual metadata update upload path (common in air-gapped deployments) 📝 **Summary:** Authenticated administrative users can upload crafted metadata update files that the product fails to validate, enabling arbitrary file writes as root and potential full system compromise. The vulnerable upload path is used in air-gapped and cloud-connected deployments and no vendor workaround is available — prioritize patching. 📈 **Impact Scope:** Authenticated admin-level upload leads to arbitrary root-owned file writes on affected Nexus Dashboard Insights and certain unified Nexus Dashboard images prior to fixed releases, with potential for full system compromise. 🛡️ **Recommended Actions:** - Apply vendor-provided updates immediately and migrate to a fixed unified Nexus Dashboard image as documented - Restrict admin access to trusted hosts/networks, enforce strong admin credential management, and rotate credentials after patching - Verify system integrity and monitor logs/audit metadata upload activity for indicators of exploitation 🪢 **Related Resources:** - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndi-afw-rJuRC5dZ - https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws40848 🏷 **Tags:** #Cybersecurity #Cisco #NexusDashboard

    Post summary

    Cisco Nexus Dashboard Insights (CVE‑2026‑20174) is a medium‑severity arbitrary file write vulnerability exploitable by authenticated admins, with vendor‑provided patches available and immediate remediation advised.

    0000055
    276 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability 🆔 **CVE-2026-20174** | 📊 CVSS: 4.9 (Medium 🟡) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Cisco Nexus Dashboard Insights (all configurations), 6.5 and earlier 🔧 **Fixed Versions:** Upgrade/migrate to fixed Nexus Dashboard release (see Cisco advisory) 🫨 **Attack Vectors:** - Authenticated remote (administrator) via malicious metadata update file - Manual metadata upload mechanism (used for air-gapped deployments; optional for cloud-connected devices) 📝 **Summary:** An authenticated administrator can upload a crafted metadata file that results in arbitrary file writes as root on Nexus Dashboard Insights, enabling modification of system binaries/configuration, persistence, and potential lateral impact. No public exploits were known at publication; apply vendor fixes immediately. 📈 **Impact Scope:** Arbitrary file write as root on affected Nexus Dashboard Insights instances; may allow modification of system binaries/configuration, persistence, and wider network impact depending on deployment. 🛡️ **Recommended Actions:** - Apply Cisco-provided updates immediately (see advisory) - Restrict and monitor administrative accounts and metadata upload operations 🪢 **Related Resources:** - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndi-afw-rJuRC5dZ - https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws40848 🏷 **Tags:** #Cybersecurity #Cisco #NexusDashboardInsights

    Post summary

    The alert announces CVE‑2026‑20174, an arbitrary file‑write vulnerability in Cisco Nexus Dashboard Insights that allows an authenticated administrator to write files as root. No exploits are known, but a patch is available and should be applied immediately.

    0000051
    276 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Cisco Nexus Dashboard Insights Arbitrary File Write (CVE-2026-20174) 📅 **Timeline:** Disclosure: Not Available; Patch: Not Available 🆔 **CVE-2026-20174** | 📊 CVSS: 4.9 (Medium 🟡) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Nexus Dashboard Insights ≤6.5, Nexus Dashboard 3.1/3.2/4.1 (pre-fix), devices running vulnerable releases 🔧 **Fixed Versions:** Upgrade to fixed Nexus Dashboard release (see advisory), Nexus Dashboard 4.2 (not vulnerable) 🫨 **Attack Vectors:** - Authenticated remote attacker with administrative credentials - Upload of crafted malicious metadata update file (manual upload) - Applicable to both air-gapped and cloud-connected deployments 📝 **Summary:** An authenticated administrator can upload a crafted metadata update file that bypasses validation, allowing arbitrary file write as root on affected Nexus Dashboard Insights instances. This enables high integrity impact and potential full system compromise across deployments running vulnerable releases. 📈 **Impact Scope:** Arbitrary file write as root enabling local root-level modifications, persistence, data tampering, and further compromise; affects all deployments running vulnerable releases. 🛡️ **Recommended Actions:** - Apply vendor updates immediately (upgrade to a fixed Nexus Dashboard release or Nexus Dashboard 4.2) - Restrict and monitor administrative account access; enforce strong authentication and least privilege - Disable or tightly control manual metadata update uploads where possible - Monitor for suspicious metadata upload activity, review logs, perform integrity checks, and restore from known-good backups if compromise is suspected 🪢 **Related Resources:** - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndi-afw-rJuRC5dZ - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndi-afw-rJuRC5dZ/csaf/cisco-sa-ndi-afw-rJuRC5dZ.json 🏷 **Tags:** #Cybersecurity #Cisco #NexusDashboard

    Post summary

    The advisory describes how an authenticated administrator can upload a crafted metadata file to achieve arbitrary root-level file writes on Nexus Dashboard Insights, and provides specific patching and mitigation guidance.

    0000054
    276 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability (CVE-2026-20174) 📅 **Timeline:** Disclosure: 2026-04-01, Patch: Not Available 🆔 **CVE-2026-20174** | 📊 CVSS: 4.9 (Medium 🟡) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Nexus Dashboard Insights 6.5 and earlier, other vulnerable releases at time of publication 🔧 **Fixed Versions:** Fixed Nexus Dashboard / Nexus Dashboard Insights release (see advisory), migrate from 6.5 and earlier to fixed release 🫨 **Attack Vectors:** - Manual metadata update file upload by an authenticated admin (requires valid administrative credentials) - Remote network-accessible metadata update feature (AV:N) but exploitation requires high‑privilege admin credentials (PR:H) 📝 **Summary:** An authenticated administrator can upload a crafted metadata update file that results in arbitrary file writes to the underlying OS as root, enabling local integrity compromise/privilege escalation. Exploitation requires valid high‑privilege admin credentials; confidentiality and availability were not reported as impacted. 📈 **Impact Scope:** Authenticated attacker with administrative credentials can write arbitrary files to the OS as root (integrity impact high; confidentiality and availability not affected per advisory). 🛡️ **Recommended Actions:** - Apply Cisco published updates to fixed Nexus Dashboard / Nexus Dashboard Insights releases immediately - Remove or restrict manual metadata upload capability where possible and enforce least privilege for accounts that can perform metadata updates - Rotate administrative credentials if compromise is suspected and monitor logs for anomalous metadata uploads or unexpected file writes - Contact Cisco TAC for assistance obtaining fixed software if needed 🪢 **Related Resources:** - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndi-afw-rJuRC5dZ - https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws40848 🏷 **Tags:** #Cybersecurity #Cisco #NexusDashboard

    Post summary

    Cisco Nexus Dashboard Insights is vulnerable to an authenticated arbitrary file write via metadata uploads; patches are available and users are advised to apply updates immediately and harden administrative controls.

    0000050
    276 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability (CVE-2026-20174) 📅 **Timeline:** Disclosure: 2026-04-01; Patch: 2026-04-01 🆔 **CVE-2026-20174** | 📊 CVSS: 4.9 (Medium 🟡) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Nexus Dashboard Insights ≤6.5, Nexus Dashboard unified image 3.1/3.2/4.1 🔧 **Fixed Versions:** Nexus Dashboard Release 4.2+, fixed releases listed in advisory 🫨 **Attack Vectors:** - Authenticated remote upload of crafted metadata file (requires administrative credentials) - Manual metadata upload path common to air-gapped deployments - Arbitrary file write to underlying OS as root (post-authentication) 📝 **Summary:** An insufficient validation bug in the metadata update feature lets an authenticated administrator upload crafted metadata that results in arbitrary file writes as root on affected Nexus Dashboard Insights instances. The primary impact is integrity (root file creation/modification); attacker access requires administrative credentials and no public exploitation is known at publication. 📈 **Impact Scope:** Root-level file creation/modification on affected Nexus Dashboard Insights deployments if attacker has admin credentials; applies to Insights ≤6.5 and unified image releases 3.1/3.2/4.1; 4.2+ not vulnerable. 🛡️ **Recommended Actions:** - Upgrade affected systems to Nexus Dashboard Release 4.2+ or the fixed releases listed in the Cisco advisory - Restrict administrative access and disable manual metadata upload where feasible - Rotate administrative credentials, audit privileged accounts, and monitor logs for suspicious metadata uploads - Obtain fixed software and guidance via Cisco TAC/PSIRT 🪢 **Related Resources:** - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndi-afw-rJuRC5dZ - https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws40848 🏷 **Tags:** #Cybersecurity #Cisco #NexusDashboard

    Post summary

    The post announces Cisco's CVE‑2026‑20174, provides detailed technical characteristics, and emphasizes remediation steps, including upgrading to patched releases and restricting administrative actions.

    0000051
    276 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Cisco Nexus Dashboard Insights Arbitrary File Write 📅 **Timeline:** Disclosure: Not available; Patch: Not available 🆔 **CVE-2026-20174** | 📊 CVSS: 4.9 (Medium 🟡) | 📈 EPSS: Not available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Nexus Dashboard Insights ≤6.5, Nexus Dashboard unified images prior to fixes 🔧 **Fixed Versions:** Fixed Nexus Dashboard release (see Cisco advisory), Nexus Dashboard Release 4.2+ 🫨 **Attack Vectors:** - Authenticated remote (requires administrative credentials) - Manual metadata-file upload (air-gapped deployments; upload option present in cloud-connected deployments) 📝 **Summary:** An authenticated administrator can upload a crafted metadata file that writes arbitrary files as root on Nexus Dashboard Insights, enabling data tampering, persistence, and potential full system compromise. Requires admin access; no exploit maturity reported. 📈 **Impact Scope:** Arbitrary file write at root privileges on affected Nexus Dashboard Insights instances; enables data tampering, persistence, and potential full system compromise. 🛡️ **Recommended Actions:** - Apply Cisco fixed releases immediately per advisory - Restrict administrative metadata upload functionality where possible - Review logs and system file integrity; hunt for indicators of compromise - Rotate administrative credentials and secrets; isolate or rebuild compromised systems if suspected 🪢 **Related Resources:** - https://www.youtube.com/watch?v=KsZ6tROaVOQ - https://en.wikipedia.org/wiki/2 🏷 **Tags:** #Cybersecurity #Cisco #NexusDashboardInsights

    Post summary

    The text announces CVE‑2026‑20174, detailing its medium severity, affected Nexus Dashboard Insights versions, and recommended mitigation steps, but provides no PoC, exploit code, or evidence of active exploitation.

    0000063
    276 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appcisconexus_dashboard---
Appcisconexus_dashboard_insights---

Explore more