Remote Information Disclosure Vulnerability in Cisco Meraki
CVE-2026-20115

6.1MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
25 March 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-20115?

A vulnerability in Cisco IOS XE Software for Cisco Meraki exposes sensitive device configuration information to remote, unauthenticated attackers. This occurs because device configuration uploads are made over an insecure tunnel. Attackers can execute an on-path attack between the compromised device and the Cisco Meraki Dashboard, which allows them to access confidential device details. Protecting your devices from this vulnerability requires immediate attention to secure communication channels.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Cisco IOS XE Software 17.14.1

Cisco IOS XE Software 17.14.1a

Cisco IOS XE Software 17.15.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.