CVE-2026-20321
Received
Received - Intake
Command Injection in Cisco APIC Web Management API
Vulnerability report for CVE-2026-20321, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-07
Last updated on: 2026-10-07
Assigner: Cisco Systems, Inc.
Description
Description
A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to execute arbitrary commands as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to insufficient input validation of user-controlled command arguments. An attacker could exploit this vulnerability by authenticating using the API and sending crafted input. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device with root-level privileges.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Cisco | Cisco | Application Policy Infrastructure Controller (APIC) 5.3(1d) |
| Cisco | Cisco | Application Policy Infrastructure Controller (APIC) 5.3(2a) |
| Cisco | Cisco | Application Policy Infrastructure Controller (APIC) 5.3(2b) |
| Cisco | Cisco | Application Policy Infrastructure Controller (APIC) 5.3(2c) |
| Cisco | Cisco | Application Policy Infrastructure Controller (APIC) 5.3(2d) |
| Cisco | Cisco | Application Policy Infrastructure Controller (APIC) 5.3(2e) |
| Cisco | Cisco | Application Policy Infrastructure Controller (APIC) 5.3(2f) |
| Cisco | Cisco | Application Policy Infrastructure Controller (APIC) 6.1(5e) |
| Cisco | Cisco | Application Policy Infrastructure Controller (APIC) 6.2(1f) |
| Cisco | Cisco | Application Policy Infrastructure Controller (APIC) 6.2(1g) |
| Cisco | Cisco | Application Policy Infrastructure Controller (APIC) 6.2(2e) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-544 | The product does not use a standardized method for handling errors throughout the code, which might introduce inconsistent error handling and resultant weaknesses. |