IT

Tracker / CVE-2026-20191

CVE-2026-20191

High 7.5

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.

Affected products and versions

cisco catalyst_center · 2.3.7.0 → 2.3.7.11
cisco catalyst_center · 3.1.3 → 3.1.6-75524.200
cisco catalyst_center_global_manager · … → 1.4.1

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References