CVE-2026-20321
CVE-2026-20321 is a medium-severity vulnerability with a CVSS 3.x base score of 6.5. The underlying weakness is classified as CWE-544.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-544
- Published:
- Last modified:
Description
A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to execute arbitrary commands as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient input validation of user-controlled command arguments. An attacker could exploit this vulnerability by authenticating using the API and sending crafted input. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device with root-level privileges.
Frequently asked questions
- What is CVE-2026-20321?
- A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to execute arbitrary commands as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient input validation of user-controlled command arguments. An attacker could exploit this vulnerability by authenticating using the API and sending crafted input. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device with root-level privileges.
- How severe is CVE-2026-20321?
- CVE-2026-20321 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-20321 being actively exploited?
- It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
- How do I fix CVE-2026-20321?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-20321 published?
- CVE-2026-20321 was published on 2026-10-07.
References
Other CWE-544 vulnerabilities
- CVE-2024-41768 — Medium (CVSS 6.5): IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause an unhandled…
- CVE-2024-47971 — Medium (CVSS 6.5): Improper error handling in firmware of some SSD DC Products may allow an attacker to enable denial of service.
- CVE-2023-29105 — Medium (CVSS 5.9): A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud…
- CVE-2025-11750 — Medium (CVSS 5.3): In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning…
- CVE-2021-47482 — Medium (CVSS 5.3): In the Linux kernel, the following vulnerability has been resolved: net: batman-adv: fix error handling Syzbot…