{"id":"CVE-2026-20042","title":"A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information.\r\n\r\nThis vulnerability ex…","summary":"A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information.\r\n\r\nThis vulnerability ex…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-295"],"vendor":"cisco","product":"nexus_dashboard","affected":["nexus_dashboard < 4.2.1"],"patched":["nexus_dashboard 4.2.1"],"published":"2026-04-01","updated":"2026-07-08","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20042","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-cbid-5YqkOSHu","label":"psirt@cisco.com"}],"tags":["nvd"],"epss":0.00293,"epssPercentile":0.19439,"ingestedAt":"2026-07-08T13:51:10.440Z","slug":"CVE-2026-20042","body":"## Overview\n\nA vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information.\r\n\r\nThis vulnerability exists because authentication details are included in the encrypted backup files. An attacker with a valid backup file and encryption password from an affected device could decrypt the backup file. The attacker could then use the authentication details in the backup file to access internal-only APIs on the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.\n\n## Affected\n\n- `nexus_dashboard < 4.2.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `nexus_dashboard 4.2.1`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}