CVE-2026-20361: SQLi in Cisco Nexus Dashboard
CVE-2026-20361 Published on September 16, 2026
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - SQL Injection
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20361 are related to SQL injection issues that are grouped under the Common Weakness Enumeration (CWE) CWE-89.
Vulnerability Analysis
CVE-2026-20361 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is a SQL Injection Vulnerability?
The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.
CVE-2026-20361 has been classified to as a SQL Injection vulnerability or weakness.
Products Associated with CVE-2026-20361
Want to know whenever a new CVE is published for Cisco Nexus Dashboard? stack.watch will email you.
Affected Versions
Cisco Nexus Dashboard:- Version 2.1(1d) is affected.
- Version 2.1(1e) is affected.
- Version 2.1(2d) is affected.
- Version 2.2(1h) is affected.
- Version 2.2(1e) is affected.
- Version 2.2(2d) is affected.
- Version 2.1(2f) is affected.
- Version 2.3(1c) is affected.
- Version 2.3(2b) is affected.
- Version 2.3(2c) is affected.
- Version 2.3(2d) is affected.
- Version 2.3(2e) is affected.
- Version 3.0(1f) is affected.
- Version 3.0(1i) is affected.
- Version 3.1(1k) is affected.
- Version 3.1(1l) is affected.
- Version 3.2(1e) is affected.
- Version 3.2(1i) is affected.
- Version 3.3(1a) is affected.
- Version 3.3(1b) is affected.
- Version 3.3(2b) is affected.
- Version 4.0(1i) is affected.
- Version 3.3(2g) is affected.
- Version 3.2(2f) is affected.
- Version 3.2(2g) is affected.
- Version 3.2(2m) is affected.
- Version 3.1(1n) is affected.
- Version 4.1(1g) is affected.
- Version 4.2.1 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.