CiscoCVE-2026-20191
Cisco Catalyst Center: path traversal
High7.5CVE-2026-20191 · Published Jul 1, 2026 · updated Sep 17, 2026
A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cisco Catalyst Center Product | <= 2.3.7.0-VA | No fix yet |
| <= 2.3.7.5-VA | No fix yet | |
| <= 2.3.7.6-VA | No fix yet | |
| <= 2.3.7.7-VA | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-22
More Cisco advisories
All Cisco| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 1 | Cisco Secure Endpoint: denial of service | High7.5 | No fix yet |
| Jul 1 | Cisco Secure Endpoint: denial of service | High7.5 | No fix yet |
| Jul 1 | Cisco Secure Endpoint: denial of service | High7.5 | No fix yet |
| Jul 1 | Cisco Secure Endpoint: denial of service | High7.5 | No fix yet |
| Jul 1 | Cisco Secure Endpoint: denial of service | High7.5 | No fix yet |
| Jul 1 | Cisco Secure Endpoint: denial of service | High7.5 | No fix yet |