This vulnerability exists because authentication details are included in the encrypted backup files. An attacker with a valid backup file and encryption password from an affected device could decrypt the backup file. The attacker could then use the authentication details in the backup file to access internal-only APIs on the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco
Cisco nexus Dashboard |
|
| Vendors & Products |
Cisco
Cisco nexus Dashboard |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability exists because authentication details are included in the encrypted backup files. An attacker with a valid backup file and encryption password from an affected device could decrypt the backup file. The attacker could then use the authentication details in the backup file to access internal-only APIs on the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. | |
| Title | Cisco Nexus Dashboard Configuration REST API Unauthorized Access Vulnerability | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2026-04-02T03:56:08.575Z
Reserved: 2025-10-08T11:59:15.354Z
Link: CVE-2026-20042
Updated: 2026-04-01T18:12:46.925Z
Status : Awaiting Analysis
Published: 2026-04-01T17:28:26.173
Modified: 2026-04-03T16:11:11.357
Link: CVE-2026-20042
No data.
OpenCVE Enrichment
Updated: 2026-04-03T08:58:37Z