---
id: CVE-2026-20168
title: "A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access.\r\n\r\nThis vulnerabili…"
summary: "A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access.\r\n\r\nThis vulnerabili…"
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-388
vendor: cisco
product: iot_field_network_director
affected:
  - iot_field_network_director < 5.0.0-117
patched:
  - iot_field_network_director 5.0.0-117
published: '2026-05-06'
updated: '2026-06-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20168'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iot-fnd-dos-n8N26Q4u
    label: psirt@cisco.com
tags:
  - nvd
epss: 0.00272
epssPercentile: 0.19867
ingestedAt: '2026-07-01T09:50:45.538Z'
---

## Overview

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access.

This vulnerability is due to insufficient file access checks. An attacker could exploit this vulnerability by submitting crafted input in the web-based management interface. A successful exploit could allow the attacker to read files that they are not authorized to access.

## Affected

- `iot_field_network_director < 5.0.0-117`

## Remediation

Upgrade past the affected range:

- `iot_field_network_director 5.0.0-117`
