{"id":"CVE-2026-20350","title":"A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands.\r\n\r\nThis vulnerability is due to improper validatio…","summary":"A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands.\r\n\r\nThis vulnerability is due to improper validatio…","severity":"medium","cvss":4.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-78"],"vendor":"Cisco","product":"Cisco ThousandEyes Enterprise Agent","affected":["thousandeyes_enterprise_agent Agent 5.0","thousandeyes_enterprise_agent Agent 4.4.4","thousandeyes_enterprise_agent Agent 4.4.3","thousandeyes_enterprise_agent Agent 4.4.2","thousandeyes_enterprise_agent Agent 4.2","thousandeyes_enterprise_agent Agent 4.1","thousandeyes_enterprise_agent Agent 4.0","thousandeyes_enterprise_agent Agent 5.1","thousandeyes_enterprise_agent Agent 5.1.2","thousandeyes_enterprise_agent Agent 5.1.3","thousandeyes_enterprise_agent Agent 5.2.0"],"published":"2026-09-16","updated":"2026-09-18","sourceUpdated":"2026-09-18T15:17:07.710","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20350","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-teva-os-command-W4GAO6jp","label":"psirt@cisco.com"},{"url":"https://software.cisco.com"}],"tags":["nvd","cve.org","csaf","vendor-advisory","cisco"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-18T03:56:09.748261Z"},"epss":0.00338,"epssPercentile":0.27268,"ingestedAt":"2026-09-16T16:37:52.181Z","slug":"CVE-2026-20350","body":"## Overview\n\nA vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands.\r\n\r\nThis vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by saving configuration details that contain malicious values. A successful exploit could allow the attacker to execute arbitrary operating system commands with root privileges. To exploit this vulnerability, the attacker must have valid administrative credentials.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **cisco-sa-teva-os-command-W4GAO6jp** · Cisco · affected: Cisco ThousandEyes Enterprise Agent, Cisco ThousandEyes Endpoint Agent · updated 2026-09-16 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-teva-os-command-W4GAO6jp)","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":25.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}