CVE-2026-20028
Received Received - Intake

Cisco Terminal Service Agent Firewall Rule Bypass

Vulnerability report for CVE-2026-20028, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewall rules associated with a different user in the system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
cisco terminal_service_agent *
cisco terminal_service_agent to 1.4.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the network driver of Cisco Terminal Service (TS) Agent. It allows an authenticated remote attacker with user-level credentials to bypass firewall rules tied to their account. The issue occurs because network connections are incorrectly mapped to user accounts. By sending specially crafted network traffic, an attacker could exploit this to inherit firewall rules from a different user on the system.

Detection Guidance

Detecting this vulnerability requires checking the version of Cisco TS Agent installed on your system. Compare the version against 1.4.3. If the version is below 1.4.3, the system is vulnerable. Use commands like 'show version' or 'dpkg -l | grep cisco-ts-agent' depending on your OS to verify the installed version.

Impact Analysis

An attacker could bypass your firewall rules, potentially accessing restricted network resources or services. This could lead to unauthorized access to sensitive data or systems, even if your account has limited permissions. The impact depends on your network configuration and the privileges of the affected user accounts.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations using affected Cisco TS Agent versions may face increased risk of data breaches, potentially resulting in legal penalties or reputational damage.

Mitigation Strategies

Immediately upgrade Cisco TS Agent to version 1.4.3 or later. Cisco has released software updates to address this issue. No workarounds are available, so upgrading is the only mitigation method.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20028. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart