Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-20174

24
FAUCET Score

CVE-2026-20174 is an arbitrary file write vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights, caused by insufficient validation of update files. This medium-severity vulnerability (CVSS 4.9) allows an authenticated, remote attacker with administrative credentials to write arbitrary files as root to the underlying operating system. Exploitation requires an authenticated attacker to manually upload a crafted metadata file, a method available in both air-gapped and cloud-connected deployments. There is no public exploit code, it is not actively exploited, and community attention remains low.

Impacted Technologies

VendorProductVersion(s)CPE
<= 6.5.0CPE matchmatch criteria
cpe:2.3:a:cisco:nexus_dashboard_insights:*:*:*:*:*:*:*:*
>= 3.1\(1k\), < 4.2.1CPE matchmatch criteria
cpe:2.3:a:cisco:nexus_dashboard:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.9MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.49%
Probability of exploitation in next 30 days
EPSS Percentile
39.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0049 is in the 36th percentile among its peer group of 3,566 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

ciscovendor investigatingvia nvd_reference
View patch

References

sec.cloudapps.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-ndi-afw-rJuRC5dZ
Vendor Advisory