CVE-2026-20191

Cisco Catalyst Center Arbitrary File Read Vulnerability

Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.009
56.8th percentile
Discovered by
Vendor
Published by the vendor
Published
Jul 1, 2026
Assigned by cisco

Description

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.

Weakness: CWE-22

Affected products

Vendor Product Category Matched by
Cisco Cisco Catalyst Center (DNA Center) Network & Security Management cna-assigner
Vendor-reported affected versions (1)
  • Cisco · Cisco Catalyst Center