CVE-2026-20174 is an arbitrary file write vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights, caused by insufficient validation of update files. This medium-severity vulnerability (CVSS 4.9) allows an authenticated, remote attacker with administrative credentials to write arbitrary files as root to the underlying operating system. Exploitation requires an authenticated attacker to manually upload a crafted metadata file, a method available in both air-gapped and cloud-connected deployments. There is no public exploit code, it is not actively exploited, and community attention remains low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.5.0CPE matchmatch criteria | cpe:2.3:a:cisco:nexus_dashboard_insights:*:*:*:*:*:*:*:* | ||
>= 3.1\(1k\), < 4.2.1CPE matchmatch criteria | cpe:2.3:a:cisco:nexus_dashboard:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.