CVE-2026-20038
Received Received - Intake

EPG Contract Bypass in Cisco Nexus 9000 ACI Mode

Vulnerability report for CVE-2026-20038, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, remote attacker to bypass configured EPG contracts. This vulnerability is due to an improper control with EPG contracts. An attacker could exploit this vulnerability by sending IPv4 or IPv6 packets using UDP source and destination ports that are assigned to DHCP traffic through an affected device. A successful exploit could allow the attacker to bypass EPG contracts on the affected device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 61 associated CPEs
Vendor Product Version / Range
Cisco Cisco NX-OS System Software in ACI Mode 15.2(1g)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(2e)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(2f)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(2g)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(2h)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(3f)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(3e)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(3g)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(4d)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(4e)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(5c)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(5d)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(1g)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(5e)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(4f)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(6e)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(6h)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(1j)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(6g)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(7f)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(7g)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(2h)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(8d)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(2j)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(8e)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(3d)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(3e)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(8f)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(8g)
Cisco Cisco NX-OS System Software in ACI Mode 15.3(1d)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(8h)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(4c)
Cisco Cisco NX-OS System Software in ACI Mode 15.3(2a)
Cisco Cisco NX-OS System Software in ACI Mode 15.2(8i)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(5h)
Cisco Cisco NX-OS System Software in ACI Mode 15.3(2b)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(3g)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(5j)
Cisco Cisco NX-OS System Software in ACI Mode 15.3(2c)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(6c)
Cisco Cisco NX-OS System Software in ACI Mode 15.3(2d)
Cisco Cisco NX-OS System Software in ACI Mode 16.1(1f)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(7e)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(8e)
Cisco Cisco NX-OS System Software in ACI Mode 15.3(2e)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(8f)
Cisco Cisco NX-OS System Software in ACI Mode 16.1(2f)
Cisco Cisco NX-OS System Software in ACI Mode 16.1(2g)
Cisco Cisco NX-OS System Software in ACI Mode 15.3(2f)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(9c)
Cisco Cisco NX-OS System Software in ACI Mode 16.1(3f)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(9d)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(6h)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(8h)
Cisco Cisco NX-OS System Software in ACI Mode 16.1(3g)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(9e)
Cisco Cisco NX-OS System Software in ACI Mode 16.1(4h)
Cisco Cisco NX-OS System Software in ACI Mode 16.1(5e)
Cisco Cisco NX-OS System Software in ACI Mode 16.2(1g)
Cisco Cisco NX-OS System Software in ACI Mode 16.0(9f)
Cisco Cisco NX-OS System Software in ACI Mode 16.2(2e)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows unauthenticated remote attackers to bypass configured endpoint group (EPG) contracts on Cisco Nexus 9000 Series Fabric Switches in ACI Mode. It occurs due to improper control mechanisms where DHCP traffic ports are always permitted, overriding user-defined contract rules.

Impact Analysis

An attacker could exploit this to bypass network security policies, potentially allowing unauthorized access to restricted network segments or data. This could lead to data breaches, unauthorized communications, or network disruption.

Compliance Impact

Bypassing EPG contracts could violate data protection requirements by allowing unauthorized access to sensitive data, potentially leading to non-compliance with GDPR, HIPAA, or other regulations. This may result in legal penalties or reputational damage.

Mitigation Strategies
  • Upgrade Cisco APIC to releases 6.0(9h), 6.1(6g), 6.2(3g), or later.
  • Upgrade Nexus 9000 Series switches to releases 16.0(9h), 16.1(6g), 16.2(3g), or later.
  • Apply a configuration knob via Cisco APIC REST API to disable DHCP implicit rules.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20038. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart