Skip to content
CiscoCVE-2026-20191

Cisco Catalyst Center: path traversal

High7.5CVE-2026-20191 · Published Jul 1, 2026 · updated Sep 17, 2026

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.

Cisco advisory

Affected versions

PackageAffectedFixed in
Cisco Catalyst Center
Product
<= 2.3.7.0-VANo fix yet
<= 2.3.7.5-VANo fix yet
<= 2.3.7.6-VANo fix yet
<= 2.3.7.7-VANo fix yet
Details and references

More Cisco advisories

All Cisco
Advisory
Cisco Secure Endpoint: denial of service
High7.5Jul 1
Cisco Secure Endpoint: denial of service
High7.5Jul 1
Cisco Secure Endpoint: denial of service
High7.5Jul 1
Cisco Secure Endpoint: denial of service
High7.5Jul 1
Cisco Secure Endpoint: denial of service
High7.5Jul 1
Cisco Secure Endpoint: denial of service
High7.5Jul 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.