CVE-2026-20321
Received Received - Intake

Command Injection in Cisco APIC Web Management API

Vulnerability report for CVE-2026-20321, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to execute arbitrary commands as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient input validation of user-controlled command arguments. An attacker could exploit this vulnerability by authenticating using the API and sending crafted input. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device with root-level privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 11 associated CPEs
Vendor Product Version / Range
Cisco Cisco Application Policy Infrastructure Controller (APIC) 5.3(1d)
Cisco Cisco Application Policy Infrastructure Controller (APIC) 5.3(2a)
Cisco Cisco Application Policy Infrastructure Controller (APIC) 5.3(2b)
Cisco Cisco Application Policy Infrastructure Controller (APIC) 5.3(2c)
Cisco Cisco Application Policy Infrastructure Controller (APIC) 5.3(2d)
Cisco Cisco Application Policy Infrastructure Controller (APIC) 5.3(2e)
Cisco Cisco Application Policy Infrastructure Controller (APIC) 5.3(2f)
Cisco Cisco Application Policy Infrastructure Controller (APIC) 6.1(5e)
Cisco Cisco Application Policy Infrastructure Controller (APIC) 6.2(1f)
Cisco Cisco Application Policy Infrastructure Controller (APIC) 6.2(1g)
Cisco Cisco Application Policy Infrastructure Controller (APIC) 6.2(2e)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-544 The product does not use a standardized method for handling errors throughout the code, which might introduce inconsistent error handling and resultant weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a command injection vulnerability in Cisco APIC's web-based management API. It allows an authenticated remote attacker with admin credentials to execute arbitrary commands as root on the affected device. The issue occurs due to insufficient input validation of user-controlled command arguments.

Impact Analysis

An attacker could gain full control over the affected Cisco APIC device, execute malicious commands, and potentially compromise the entire network infrastructure. This could lead to data breaches, unauthorized access, or disruption of services.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating compliance requirements such as GDPR (data protection) and HIPAA (health information security). Organizations may face legal penalties, reputational damage, and loss of trust.

Mitigation Strategies
  • Upgrade Cisco APIC to the fixed software releases provided in Cisco's security advisory.
  • Ensure administrative credentials are secure and limit access to trusted users only.
  • Monitor network traffic for unusual API requests or command execution patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20321. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart