Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to …

Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function. The requester receives a response indicating that access was denied, but the actual function is executed regardless of that.

Affected products

n/a
  • ==n/a
Dismissed
(no matching packages found)
Permalink CVE-2026-71203
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
changedetection.io: Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Schema

changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get() method carries neither @auth.check_token nor @validate_openapi_request. An unauthenticated client can retrieve the full merged OpenAPI schema (all endpoint paths, parameters, and registered processor plugins) even when API access control is enabled and every sibling /api/v1/* route correctly requires the key.

Affected products

changedetection.io
  • ==0.55.7
Dismissed
(no matching packages found)
Permalink CVE-2026-9081
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Langflow OSS is affected by server-side request forgery in provider validation and API request functionality

IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. The function accepts a user-supplied OLLAMA_BASE_URL parameter and passes it directly to requests.get() without validation, scheme/host allowlisting, or filtering of private IP ranges (loopback, RFC1918, link-local addresses).

References

Affected products

Langflow OSS
  • =<1.10.3
Dismissed
(max. allowed matches exceeded)
Permalink CVE-2026-20301
8.6 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability.

Affected products

IOS
  • ==15.2(4)E10a
  • ==15.2(4)EA8
  • ==15.2(1)SY8
  • ==15.2(8)E
  • ==15.8(3)M3a
  • ==15.5(1)SY9
  • ==15.7(3)M9
  • ==15.9(3)M12
  • ==15.9(3)M3
  • ==15.2(4)E9
  • ==15.2(7)E2
  • ==15.2(7)E10
  • ==15.9(3)M
  • ==15.2(2)E10c
  • ==15.8(3)M3
  • ==15.2(8)E1
  • ==15.2(8)E5
  • ==15.5(1)SY15
  • ==15.4(1)SY4
  • ==15.8(3)M0b
  • ==15.2(7)E0b
  • ==15.2(7)E4
  • ==15.7(3)M8
  • ==15.8(3)M7
  • ==15.8(3)M0a
  • ==15.8(3)M1
  • ==15.9(3)M9a
  • ==15.9(3)M7a
  • ==15.7(3)M2
  • ==15.9(3)M8
  • ==15.5(1)SY8
  • ==15.9(3)M3b
  • ==15.2(8)E7
  • ==15.9(3)M9
  • ==15.5(1)SY11
  • ==15.7(3)M10a
  • ==15.7(3)M4
  • ==15.5(1)SY4
  • ==15.2(4)E10c
  • ==15.7(3)M6
  • ==15.7(3)M3
  • ==15.2(7)E13
  • ==15.9(3)M6a
  • ==15.2(6)E1s
  • ==15.5(1)SY12
  • ==15.2(4)E7
  • ==15.7(3)M4a
  • ==15.2(6)E2b
  • ==15.8(3)M8
  • ==15.2(7)E12
  • ==15.9(3)M1
  • ==15.2(4)E10
  • ==15.5(1)SY7
  • ==15.5(1)SY1
  • ==15.2(7)E1
  • ==15.9(3)M5
  • ==15.2(2)E8
  • ==15.2(7)E2b
  • ==15.2(6)E2
  • ==15.2(8)E8
  • ==15.9(3)M3a
  • ==15.9(3)M4
  • ==15.8(3)M4
  • ==15.2(6)E2a
  • ==15.2(7)E9
  • ==15.2(7)E0s
  • ==15.9(3)M6b
  • ==15.2(6)E1
  • ==15.9(3)M6
  • ==15.5(1)SY3
  • ==15.9(3)M7
  • ==15.9(3)M8a
  • ==15.2(7)E3k
  • ==15.2(2)E10a
  • ==15.2(2)E9a
  • ==15.8(3)M6
  • ==15.8(3)M5
  • ==15.5(1)SY13
  • ==15.8(3)M
  • ==15.7(3)M10b
  • ==15.2(8)E4
  • ==15.2(8)E6
  • ==15.2(4)E10d
  • ==15.2(8)E3
  • ==15.5(1)SY17
  • ==15.2(1)SY6
  • ==15.2(7)E8
  • ==15.9(3)M4a
  • ==15.2(7)E14
  • ==15.2(6)E1a
  • ==15.2(4)E6
  • ==15.2(4)E8
  • ==15.9(3)M11
  • ==15.8(3)M1a
  • ==15.2(7)E5
  • ==15.2(7)E1a
  • ==15.6(2)SP5
  • ==15.2(7)E
  • ==15.6(2)SP9
  • ==15.2(4)EA9
  • ==15.2(7)E3
  • ==15.5(1)SY5
  • ==15.9(3)M10
  • ==15.2(7)E0a
  • ==15.6(2)SP6
  • ==15.9(3)M8b
  • ==15.8(3)M2a
  • ==15.7(3)M7
  • ==15.7(3)M4b
  • ==15.2(7)E7
  • ==15.2(2)E9
  • ==15.9(3)M0a
  • ==15.5(1)SY2
  • ==15.2(6)E3
  • ==15.5(1)SY14
  • ==15.2(4)EA7
  • ==15.8(3)M9
  • ==15.9(3)M13
  • ==15.6(2)SP4
  • ==15.5(1)SY6
  • ==15.6(2)SP8
  • ==15.5(1)SY16
  • ==15.2(2)E10
  • ==15.8(3)M3b
  • ==15.2(8)E2
  • ==15.2(2)E10b
  • ==15.6(2)SP8a
  • ==15.9(3)M2
  • ==15.8(3)M2
  • ==15.2(1)SY7
  • ==15.9(3)M2a
  • ==15.2(4)E10e
  • ==15.2(4)E10b
  • ==15.7(3)M5
  • ==15.7(3)M10
  • ==15.2(4)EA9a
  • ==15.2(7)E6
  • ==15.6(2)SP7
  • ==15.5(1)SY10
  • ==15.2(7)E11
Cisco IOS XE Software
  • ==17.15.1y
  • ==17.3.1x
  • ==16.12.1z1
  • ==16.6.5b
  • ==16.12.9
  • ==16.9.2s
  • ==16.12.1s
  • ==17.18.1
  • ==17.15.4
  • ==16.6.5
  • ==17.12.1z2
  • ==17.12.1x
  • ==16.9.3h
  • ==16.9.7
  • ==17.1.2
  • ==16.8.1a
  • ==17.12.5
  • ==17.12.4b
  • ==17.7.1a
  • ==17.2.1
  • ==3.11.7E
  • ==16.7.1
  • ==16.10.1a
  • ==3.11.3aE
  • ==16.12.4
  • ==17.3.1w
  • ==17.3.3
  • ==17.6.8
  • ==16.12.13
  • ==16.10.1d
  • ==16.6.6
  • ==16.9.1b
  • ==3.16.10bS
  • ==16.9.8
  • ==17.10.1b
  • ==17.9.6a
  • ==17.11.1a
  • ==17.9.1
  • ==17.12.1z5
  • ==16.12.7
  • ==17.9.4a
  • ==16.12.5
  • ==17.6.1x
  • ==17.15.4a
  • ==16.10.3
  • ==17.12.3a
  • ==16.10.1s
  • ==16.12.4a
  • ==17.2.1r
  • ==17.7.1b
  • ==17.12.7
  • ==16.12.2a
  • ==17.3.6
  • ==16.12.2
  • ==17.4.2
  • ==17.9.5b
  • ==16.9.1d
  • ==17.9.1y1
  • ==17.1.1a
  • ==17.1.3
  • ==17.3.5a
  • ==16.11.1s
  • ==3.18.8aSP
  • ==16.12.1c
  • ==3.11.13E
  • ==3.8.10cE
  • ==17.15.4b
  • ==16.9.5
  • ==16.6.5a
  • ==17.18.3a
  • ==17.15.1b
  • ==17.12.4a
  • ==17.3.5
  • ==16.12.1t
  • ==16.6.4a
  • ==17.6.4
  • ==17.9.5d
  • ==17.12.1y
  • ==16.7.4
  • ==17.11.1
  • ==17.17.1
  • ==16.12.8
  • ==17.18.1y
  • ==16.9.8b
  • ==16.9.1a
  • ==17.9.5c
  • ==16.6.3
  • ==3.11.5E
  • ==17.9.1w
  • ==3.8.10dE
  • ==17.12.1
  • ==17.7.1
  • ==17.13.1a
  • ==17.9.2a
  • ==17.9.7b
  • ==3.11.14E
  • ==17.6.7
  • ==3.11.12E
  • ==17.15.3a
  • ==17.15.5
  • ==17.3.8
  • ==3.11.8E
  • ==3.18.9SP
  • ==17.4.1
  • ==17.9.3a
  • ==17.5.1a
  • ==17.9.5a
  • ==17.15.2c
  • ==17.3.2
  • ==17.12.1z4
  • ==17.4.1c
  • ==16.10.1c
  • ==17.14.1a
  • ==16.12.10a
  • ==16.9.3
  • ==17.1.1s
  • ==17.6.6a
  • ==17.3.4c
  • ==17.8.1
  • ==16.12.1z2
  • ==17.6.2
  • ==17.9.4
  • ==16.12.15
  • ==17.12.6a
  • ==17.3.1
  • ==17.4.1b
  • ==17.4.1a
  • ==17.12.3
  • ==17.18.3
  • ==17.15.4c
  • ==3.11.10E
  • ==16.12.1w
  • ==16.12.1
  • ==16.12.6a
  • ==17.6.1z
  • ==17.12.1z
  • ==17.15.3b
  • ==16.12.1x
  • ==16.9.6
  • ==17.14.1
  • ==17.15.1
  • ==16.6.8
  • ==16.12.11
  • ==17.6.3
  • ==17.18.1a
  • ==17.9.5e
  • ==17.15.1x
  • ==17.3.1z
  • ==16.10.1
  • ==17.10.1a
  • ==16.6.4s
  • ==17.3.8a
  • ==17.9.7
  • ==17.12.5d
  • ==16.9.8a
  • ==16.8.1c
  • ==16.6.7a
  • ==16.9.3a
  • ==16.8.1e
  • ==16.10.2
  • ==16.6.9
  • ==17.2.1a
  • ==16.9.5f
  • ==17.18.2
  • ==17.1.1t
  • ==26.2.1ea
  • ==17.15.2b
  • ==17.18.1w
  • ==16.9.2
  • ==17.2.2
  • ==17.9.2
  • ==16.9.1
  • ==17.3.5b
  • ==16.9.4
  • ==16.6.7
  • ==16.10.1e
  • ==3.11.4E
  • ==17.6.1a
  • ==3.11.11E
  • ==17.12.1z1
  • ==17.6.6
  • ==17.12.6b
  • ==16.11.1b
  • ==16.8.1
  • ==16.11.2
  • ==17.15.2
  • ==17.18.1z
  • ==17.9.3
  • ==16.9.2a
  • ==17.6.1
  • ==17.12.1a
  • ==3.11.3E
  • ==16.7.3
  • ==17.10.1
  • ==17.12.1z6
  • ==16.7.2
  • ==16.8.1b
  • ==16.10.1f
  • ==16.12.1z
  • ==17.3.2a
  • ==16.12.6
  • ==17.15.4s1
  • ==16.12.2t
  • ==17.7.2
  • ==16.12.2s
  • ==17.3.7
  • ==17.9.1x1
  • ==16.12.3
  • ==17.3.4b
  • ==16.12.16
  • ==16.6.2
  • ==3.11.9E
  • ==17.15.5a
  • ==17.12.2
  • ==17.6.8a
  • ==17.9.7a
  • ==16.8.1d
  • ==16.12.1y
  • ==17.1.1
  • ==17.3.4
  • ==17.6.5a
  • ==17.12.5a
  • ==17.12.2a
  • ==16.11.1
  • ==17.6.5
  • ==17.15.3
  • ==17.15.1a
  • ==3.11.6E
  • ==16.12.12
  • ==17.15.4d
  • ==17.12.7b
  • ==17.3.4a
  • ==16.9.3s
  • ==16.7.1a
  • ==16.12.3a
  • ==3.16.10aS
  • ==16.11.1c
  • ==17.3.3a
  • ==16.12.1a
  • ==17.9.1x
  • ==17.9.1a
  • ==17.8.1a
  • ==16.10.1b
  • ==16.9.1c
  • ==17.9.5f
  • ==17.6.1z1
  • ==16.12.14
  • ==16.11.1a
  • ==16.8.1s
  • ==17.12.1w
  • ==16.12.10
  • ==17.2.1v
  • ==16.6.10
  • ==17.12.6
  • ==17.9.8
  • ==17.4.2a
  • ==17.15.1w
  • ==17.15.2a
  • ==17.9.1y
  • ==16.12.5a
  • ==17.12.1z3
  • ==16.10.1g
  • ==17.2.3
  • ==16.8.3
  • ==17.16.1a
  • ==16.9.1s
  • ==16.12.5b
  • ==16.9.4c
  • ==16.6.4
  • ==17.12.5b
  • ==17.5.1
  • ==16.12.3s
  • ==17.12.5c
  • ==17.9.9
  • ==17.6.3a
  • ==17.12.7a
  • ==26.1.1a
  • ==17.12.4
  • ==26.1.1
  • ==17.9.5
  • ==17.3.1a
  • ==17.16.1
  • ==17.18.1x
  • ==17.9.6
  • ==17.13.1
  • ==16.8.2
  • ==16.7.1b
Dismissed
(no matching packages found)
Permalink CVE-2026-12410
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
CCleaner local privilege escalation via link following on uninstall

Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated integrity.

Affected products

CCleaner
  • <7.10.1464
Dismissed
(no matching packages found)
Permalink CVE-2026-61484
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Affected products

Lucy
  • *
Dismissed
(no matching packages found)
Permalink CVE-2026-8709
9.9 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Privilege escalation in Progress MarkLogic Server REST document patch operation

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.

Affected products

MarkLogic Server
  • <12.0.3
  • <11.3.6
Dismissed
(no matching packages found)
Permalink CVE-2026-71207
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Stock-Inventory-Management-System: Unauthenticated SQL Injection and Hardcoded Credentials in login.php Enable Full Authentication Bypass

The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password values to $_SESSION and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. An unauthenticated remote attacker can submit a payload such as ' OR '1'='1 in the login form to bypass authentication entirely. The same script additionally contains hardcoded administrative credentials (admin/neola) in a post-login conditional check, providing a second, independent full-authentication-bypass path.

Affected products

Stock-Inventory-Management-System
  • =<1.0
Dismissed
(no matching packages found)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Apache Answer: Denial of service via crafted Accept-Language header parsing

Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Affected products

Apache Answer
  • =<2.0.1
Dismissed
(no matching packages found)
Permalink CVE-2026-20267
9.0 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco IOS XE Software Security Hardening Release

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by&nbsp;CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar&nbsp;CWE-284.

Affected products

Cisco IOS XE Software
  • ==17.15.1y
  • ==17.3.1x
  • ==16.12.1z1
  • ==16.6.5b
  • ==16.12.9
  • ==17.18.1
  • ==16.9.2s
  • ==16.12.1s
  • ==17.15.4
  • ==17.12.1z2
  • ==16.6.5
  • ==17.12.1x
  • ==16.9.3h
  • ==16.9.7
  • ==17.1.2
  • ==17.12.5
  • ==16.8.1a
  • ==17.12.4b
  • ==17.7.1a
  • ==17.2.1
  • ==16.7.1
  • ==16.10.1a
  • ==16.12.4
  • ==17.3.1w
  • ==17.6.8
  • ==17.3.3
  • ==16.12.13
  • ==16.8.2
  • ==16.6.6
  • ==16.9.1b
  • ==17.10.1b
  • ==17.9.6a
  • ==16.9.8
  • ==17.11.1a
  • ==17.9.1
  • ==17.12.1z5
  • ==16.12.7
  • ==17.9.4a
  • ==16.12.5
  • ==17.6.1x
  • ==17.15.4a
  • ==16.10.3
  • ==17.12.3a
  • ==17.12.7
  • ==16.10.1s
  • ==17.7.1b
  • ==17.2.1r
  • ==16.12.4a
  • ==17.3.6
  • ==16.12.2a
  • ==16.12.2
  • ==17.9.5b
  • ==17.4.2
  • ==16.9.1d
  • ==17.9.1y1
  • ==17.1.1a
  • ==17.1.3
  • ==17.3.5a
  • ==17.15.4b
  • ==16.11.1s
  • ==16.12.1c
  • ==16.9.5
  • ==16.6.5a
  • ==17.18.3a
  • ==17.15.1b
  • ==17.12.4a
  • ==17.3.5
  • ==16.9.6
  • ==16.12.1t
  • ==17.6.4
  • ==17.9.5d
  • ==16.6.4a
  • ==17.12.1y
  • ==16.7.4
  • ==17.11.1
  • ==17.17.1
  • ==16.12.8
  • ==17.18.1y
  • ==16.9.8b
  • ==17.9.5c
  • ==16.9.1a
  • ==16.6.3
  • ==17.9.1w
  • ==17.9.7b
  • ==17.12.1
  • ==17.13.1a
  • ==17.7.1
  • ==17.9.2a
  • ==17.6.7
  • ==17.15.3a
  • ==17.15.5
  • ==17.3.8
  • ==17.4.1
  • ==17.9.3a
  • ==17.12.1z4
  • ==17.9.5a
  • ==17.15.2c
  • ==17.4.1c
  • ==17.3.2
  • ==17.5.1a
  • ==17.14.1a
  • ==16.10.1c
  • ==16.12.10a
  • ==16.9.3
  • ==17.1.1s
  • ==17.6.6a
  • ==17.3.4c
  • ==17.8.1
  • ==16.12.1z2
  • ==17.9.4
  • ==16.12.15
  • ==17.6.2
  • ==17.12.6a
  • ==17.3.1
  • ==17.4.1b
  • ==17.4.1a
  • ==17.12.3
  • ==17.18.3
  • ==17.15.4c
  • ==16.12.1w
  • ==16.12.1
  • ==16.12.6a
  • ==17.6.1z
  • ==17.12.1z
  • ==17.15.3b
  • ==17.14.1
  • ==16.12.11
  • ==16.12.1x
  • ==17.15.1
  • ==17.18.1a
  • ==16.6.8
  • ==17.6.3
  • ==17.12.5d
  • ==17.9.5e
  • ==17.15.1x
  • ==17.9.7
  • ==16.10.1
  • ==17.10.1a
  • ==16.6.4s
  • ==17.3.8a
  • ==17.3.1z
  • ==16.9.8a
  • ==16.8.1c
  • ==16.6.7a
  • ==16.9.3a
  • ==16.8.1e
  • ==16.10.2
  • ==16.6.9
  • ==17.2.1a
  • ==17.18.2
  • ==16.9.5f
  • ==17.1.1t
  • ==17.15.2b
  • ==17.18.1w
  • ==16.9.2
  • ==17.2.2
  • ==17.9.2
  • ==16.9.1
  • ==17.3.5b
  • ==16.9.4
  • ==17.12.6b
  • ==17.12.1z1
  • ==16.6.7
  • ==16.10.1e
  • ==17.6.1a
  • ==17.6.6
  • ==17.15.2
  • ==16.11.1b
  • ==17.18.1z
  • ==16.11.2
  • ==16.8.1
  • ==17.9.3
  • ==16.9.2a
  • ==17.12.1a
  • ==17.6.1
  • ==16.7.3
  • ==17.10.1
  • ==17.12.1z6
  • ==17.15.7
  • ==16.7.2
  • ==16.8.1b
  • ==16.10.1f
  • ==16.12.1z
  • ==17.15.4s1
  • ==17.3.2a
  • ==16.12.6
  • ==17.7.2
  • ==16.12.2t
  • ==16.12.2s
  • ==17.3.7
  • ==17.9.1x1
  • ==16.12.3
  • ==17.3.4b
  • ==16.12.16
  • ==16.6.2
  • ==17.15.5a
  • ==17.12.2
  • ==17.6.8a
  • ==17.9.7a
  • ==16.8.1d
  • ==17.6.5a
  • ==16.12.1y
  • ==17.1.1
  • ==17.12.5a
  • ==17.3.4
  • ==17.12.2a
  • ==16.11.1
  • ==17.6.5
  • ==17.15.3
  • ==17.15.1a
  • ==16.12.12
  • ==17.15.4d
  • ==17.12.7b
  • ==17.3.4a
  • ==16.9.3s
  • ==16.7.1a
  • ==16.12.3a
  • ==16.11.1c
  • ==17.3.3a
  • ==16.12.1a
  • ==17.9.1x
  • ==17.9.1a
  • ==17.8.1a
  • ==16.10.1b
  • ==17.9.5f
  • ==16.9.1c
  • ==17.6.1z1
  • ==16.12.14
  • ==17.12.1w
  • ==17.12.6
  • ==16.11.1a
  • ==16.12.10
  • ==17.9.8
  • ==17.2.1v
  • ==16.8.1s
  • ==16.6.10
  • ==17.4.2a
  • ==17.15.1w
  • ==17.15.2a
  • ==17.9.1y
  • ==16.12.5a
  • ==17.12.1z3
  • ==16.10.1g
  • ==17.2.3
  • ==16.8.3
  • ==17.16.1a
  • ==16.9.1s
  • ==16.12.5b
  • ==16.9.4c
  • ==16.6.4
  • ==17.12.5b
  • ==17.5.1
  • ==17.12.5c
  • ==16.12.3s
  • ==17.9.9
  • ==17.6.3a
  • ==17.12.7a
  • ==26.1.1a
  • ==17.12.4
  • ==26.1.1
  • ==17.9.5
  • ==17.16.1
  • ==17.18.1x
  • ==17.3.1a
  • ==17.9.6
  • ==17.13.1
  • ==16.10.1d
  • ==16.7.1b