This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by saving configuration details that contain malicious values. A successful exploit could allow the attacker to execute arbitrary operating system commands with root privileges. To exploit this vulnerability, the attacker must have valid administrative credentials.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 18 Sep 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco
Cisco thousandeyes Enterprise Agent |
|
| Vendors & Products |
Cisco
Cisco thousandeyes Enterprise Agent |
Wed, 16 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by saving configuration details that contain malicious values. A successful exploit could allow the attacker to execute arbitrary operating system commands with root privileges. To exploit this vulnerability, the attacker must have valid administrative credentials. | |
| Title | Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2026-09-18T14:54:58.020Z
Reserved: 2025-10-08T11:59:15.414Z
Link: CVE-2026-20350
Updated: 2026-09-17T15:26:25.743Z
Status : Awaiting Analysis
Published: 2026-09-16T21:17:12.380
Modified: 2026-09-18T15:17:07.710
Link: CVE-2026-20350
No data.
OpenCVE Enrichment
Updated: 2026-09-17T20:45:16Z