Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-20046

CVE-2026-20046: 1 tracked advisory record across Cisco. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Cisco

1 advisory
  • Advisory severityHigh8.8

    High [CVE-2026-20040 +1] Cisco IOS XR Software CLI Privilege Escalation Vulnerabilities

    cisco-sa-iosxr-privesc-bF8D5U4WSource published Source updated

    This bulletin covers 2 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    Multiple vulnerabilities in Cisco IOS XR Software could allow an authenticated, local attacker to execute commands as root on an underlying operating system or gain full administrative control of an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. A workaround is available for one of the vulnerabilities. This advisory is part of the March 2026 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and l…

    Related products — impact not confirmed
    • Cisco IOS XR Software
    Source-reported affected versions
    • Scope: The vulnerability described in CVE-2026-20040 affects Cisco IOS XR Software, regardless of device configuration.
    • 25.1 and earlier — Migrate to a fixed release
    • Release 25.2 (first fixed: 25.2.21 (Mar 2026) / 25.2.2)
    • 25.3 — Migrate to a fixed release / Not affected

    2 more entries in the full advisory.

    Source-reported fixed versions
    • 25.2.21 (Mar 2026) / 25.2.2
    • 25.4.2 (Mar 2026) / Not affected
    • Not affected
    Mitigation guidance
    • Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
    • Release 25.1 and earlier: migrate to a fixed release.
    • Release 25.2: upgrade to 25.2.21 (Mar 2026) / 25.2.2.
    • Release 25.3: migrate to a fixed release / Not affected.

    2 more entries in the full advisory.

    Workarounds
    • CVE-2026-20040: There are no workarounds that address this vulnerability.
    • CVE-2026-20046: There is a workaround only for devices that have TACACS+ authentication, authorization, and accounting (AAA) command authorization configured. Administrators can use this feature to permit access only to commands that non-administrative users require and deny access to all other commands.
    • While this workaround has been deployed and was proven successful in a test environment, customers should determine the applicability and effectiveness in their own environment and under their own use conditions. Customers should be aware that any workaround or mitigation that is implemented may negatively impact the functionality or performance of their network based on intrinsic customer depl…

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery