---
id: CVE-2026-20191
title: "A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.&nbsp;\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input"
summary: "A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.&nbsp;\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input. An attack…"
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: cisco
product: catalyst_center
affected:
  - 'catalyst_center >= 2.3.7.0, <= 2.3.7.11'
  - 'catalyst_center >= 3.1.3, < 3.1.6-75524.200'
  - catalyst_center_global_manager < 1.4.1
patched:
  - catalyst_center 3.1.6-75524.200
  - catalyst_center_global_manager 1.4.1
published: '2026-07-01'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T19:41:27.380'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20191'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catc-file-read-wLH2vf8X
    label: psirt@cisco.com
tags:
  - nvd
epss: 0.00648
epssPercentile: 0.49631
ingestedAt: '2026-09-17T20:28:02.740Z'
---

## Overview

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.&nbsp;

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.

## Affected

- `catalyst_center >= 2.3.7.0, <= 2.3.7.11`
- `catalyst_center >= 3.1.3, < 3.1.6-75524.200`
- `catalyst_center_global_manager < 1.4.1`

## Remediation

Upgrade past the affected range:

- `catalyst_center 3.1.6-75524.200`
- `catalyst_center_global_manager 1.4.1`
