CVE-2026-20032: medium-severity vulnerability in Cisco NX-OS Software
Cisco NX-OS Software Python Sandbox Escape Vulnerability
Published
10Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.4
exploitation probability
—
observed exploitation
nono source reports it
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by manipulating specific functions within the Python interpreter. A successful exploit could allow an attacker to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected products
Cisco · Cisco NX-OS SoftwareRelated CVEs — Cisco NX-OS Software
In the same product, most dangerous first.
CVE-2024-20399MEDIUMCisco NX-OS Software CLI Command Injection VulnerabilityEPSS 4.3%KEVCVE-2022-20650HIGHCisco NX-OS Software NX-API Command Injection VulnerabilityEPSS 14.5%CVE-2022-20624HIGHCisco NX-OS Software Cisco Fabric Services Over IP Denial of Service VulnerabilityEPSS 12.4%CVE-2022-20623HIGHCisco Nexus 9000 Series Switches Bidirectional Forwarding Detection Denial of Service VulnerabilityEPSS 11.9%CVE-2022-20625MEDIUMCisco FXOS and NX-OS Software Cisco Discovery Protocol Service Denial of Service VulnerabilityEPSS 3.3%CVE-2025-20292MEDIUMCisco NXOS Software Command Injection VulnerabilityEPSS 3.2%