CVE-2026-20037
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/02/2026
Last modified:
27/02/2026
Description
A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authenticated, local attacker with read-only privileges to modify files and perform unauthorized actions on an affected system.<br />
&nbsp;<br />
This vulnerability exists because unnecessary privileges are given to the user. An attacker could exploit this vulnerability by authenticating to a device as a read-only user and connecting to the NX-OS CLI. A successful exploit could allow the attacker to create or overwrite files in the file system or perform limited privileged actions on an affected device.&nbsp; &nbsp;
Impact
Base Score 3.x
4.40
Severity 3.x
MEDIUM



