{"id":"CVE-2026-20032","title":"A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating system of an affecte…","summary":"A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating system of an affecte…","severity":"medium","cvss":4.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-653"],"vendor":"Cisco","product":"Cisco NX-OS Software","affected":["nx-os_software 8.2(5)","nx-os_software 7.3(5)D1(1)","nx-os_software 8.4(2)","nx-os_software 8.4(3)","nx-os_software 9.2(3)","nx-os_software 8.2(1)","nx-os_software 7.3(1)D1(1)","nx-os_software 9.2(2v)","nx-os_software 7.3(0)D1(1)","nx-os_software 7.3(4)D1(1)","nx-os_software 9.2(1)","nx-os_software 9.2(2t)","nx-os_software 9.2(3y)","nx-os_software 9.3(2)","nx-os_software 7.3(1)DY(1)","nx-os_software 8.1(1)","nx-os_software 8.2(2)","nx-os_software 8.3(2)","nx-os_software 7.3(2)D1(3a)","nx-os_software 9.2(4)","nx-os_software 8.1(2)","nx-os_software 7.3(3)D1(1)","nx-os_software 8.2(3)","nx-os_software 8.3(1)","nx-os_software 8.4(1)","nx-os_software 8.1(1b)","nx-os_software 7.3(0)DX(1)","nx-os_software 7.3(2)D1(1)","nx-os_software 9.3(1)","nx-os_software 7.3(2)D1(2)","nx-os_software 8.2(4)","nx-os_software 7.3(0)DY(1)","nx-os_software 9.3(1z)","nx-os_software 9.2(2)","nx-os_software 8.1(2a)","nx-os_software 7.3(2)D1(3)","nx-os_software 8.1(1a)","nx-os_software 8.4(1a)","nx-os_software 9.3(3)","nx-os_software 7.3(2)D1(1d)","nx-os_software 9.3(4)","nx-os_software 7.3(6)D1(1)","nx-os_software 8.2(6)","nx-os_software 9.3(5)","nx-os_software 8.4(2a)","nx-os_software 8.4(2b)","nx-os_software 8.5(1)","nx-os_software 9.3(6)","nx-os_software 8.4(4)","nx-os_software 7.3(7)D1(1)"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T17:16:54.480","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20032","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-mppe-dhKZAFgb","label":"psirt@cisco.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-07T16:38:22.257Z","slug":"CVE-2026-20032","body":"## Overview\n\nA vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating system of an affected&nbsp;device.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by manipulating specific functions within the Python interpreter. A successful exploit could allow an attacker to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":24.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}