Python Interpreter Vulnerability in Cisco NX-OS Software
CVE-2026-20032

4.4MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
7 October 2026

Badges

👾 Exploit Exists

What is CVE-2026-20032?

A security flaw in the Python interpreter of Cisco NX-OS Software allows authenticated, local users with limited privileges to escape the Python sandbox. This vulnerability arises from inadequate validation of user-supplied input, enabling attackers to manipulate specific functions within the interpreter. If successfully exploited, this could permit execution of arbitrary commands on the underlying operating system with the privileges of the authenticated user, posing a significant security risk.

Affected Version(s)

Cisco NX-OS Software 8.2(5)

Cisco NX-OS Software 7.3(5)D1(1)

Cisco NX-OS Software 8.4(2)

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.