LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-20046

cisco · ios xr

Published
CVSS8.8
Severityhigh
WeaknessCWE-264
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerability is due to incorrect mapping of a command to task groups within the source code. An attacker with a low-privileged account could exploit this vulnerability by using the CLI command to bypass the task group–based checks. A successful exploit could allow the attacker to elevate privileges and perform actions on an affected device without authorization checks.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-20046

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-20046.