CVE-2026-20161 is a local privilege escalation vulnerability affecting Cisco ThousandEyes Enterprise Agent's command-line interface that permits authenticated users with minimal privileges to overwrite arbitrary files through symbolic link manipulation and inadequate file access controls. The vulnerability carries a CVSS score of 5.5 (Medium) with a local attack vector requiring low user privileges and no user interaction. The attack has low complexity and could result in high integrity impact, though confidentiality and availability are not affected. The EPSS score of 0.00012 indicates minimal observed exploitation activity relative to the broader CVE landscape. There is currently no evidence of active exploitation, no public exploit code availability, and the vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog or industry hot lists. The combination of low EPSS score and inactive threat status suggests this remains a theoretical risk with limited real-world weaponization at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cisco | Cisco ThousandEyes Enterprise Agent | Agent 4.0, Agent 4.1, Agent 4.2, Agent 4.4.2, Agent 4.4.3, Agent 4.4.4, Agent 5.0, Agent 5.1, Agent 5.1.2CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.