CVE-2026-20046 identifies a high-severity privilege escalation vulnerability in Cisco IOS XR Software, caused by incorrect task group assignment for a specific CLI command. An authenticated, low-privileged local attacker can exploit this flaw to bypass authorization checks and gain full administrative control of an affected device. This vulnerability carries a CVSS score of 8.8 (High), indicating significant potential impact. Currently, there is no evidence of active exploitation, public exploit code availability, or significant community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 25.2.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco IOS XR Software CLI Privilege Escalation Vulnerabilities
Mar 11, 2026Cisco IOS XR Software CLI Privilege Escalation Vulnerabilities
Mar 11, 2026Cisco IOS XR Software CLI Privilege Escalation Vulnerabilities
Mar 11, 2026Cisco IOS XR Software CLI Privilege Escalation Vulnerabilities
Mar 11, 2026Cisco IOS XR Software CLI Privilege Escalation Vulnerabilities
Mar 11, 2026