---
id: CVE-2026-20308
title: "A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device.\r\n\r\nThis vulnerabilit…"
summary: "A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device.\r\n\r\nThis vulnerabilit…"
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-269
vendor: Cisco
product: Cisco IOS XE Software
affected:
  - ios_xe_software 17.2.1a
  - ios_xe_software 16.12.1y
  - ios_xe_software 16.12.3s
  - ios_xe_software 16.12.1w
  - ios_xe_software 16.9.1d
  - ios_xe_software 17.3.1
  - ios_xe_software 16.9.4c
  - ios_xe_software 17.2.1
  - ios_xe_software 16.9.1b
  - ios_xe_software 16.9.2s
  - ios_xe_software 16.12.4
  - ios_xe_software 16.12.3a
  - ios_xe_software 17.1.1s
  - ios_xe_software 16.11.1a
  - ios_xe_software 16.11.1b
  - ios_xe_software 16.9.1s
  - ios_xe_software 16.9.3h
  - ios_xe_software 16.9.1c
  - ios_xe_software 16.10.1f
  - ios_xe_software 17.2.1v
  - ios_xe_software 16.9.3a
  - ios_xe_software 16.12.1a
  - ios_xe_software 16.12.1x
  - ios_xe_software 16.10.1c
  - ios_xe_software 16.12.3
  - ios_xe_software 16.11.2
  - ios_xe_software 16.12.2s
  - ios_xe_software 16.10.1b
  - ios_xe_software 16.9.6
  - ios_xe_software 16.9.2
  - ios_xe_software 16.10.1
  - ios_xe_software 16.12.1t
  - ios_xe_software 16.9.1
  - ios_xe_software 16.9.3s
  - ios_xe_software 16.12.2
  - ios_xe_software 16.11.1
  - ios_xe_software 16.9.3
  - ios_xe_software 16.11.1s
  - ios_xe_software 16.12.1
  - ios_xe_software 17.1.1
  - ios_xe_software 17.1.2
  - ios_xe_software 16.10.1d
  - ios_xe_software 17.1.1t
  - ios_xe_software 16.9.4
  - ios_xe_software 16.12.2t
  - ios_xe_software 16.9.5
  - ios_xe_software 16.10.1e
  - ios_xe_software 16.10.1a
  - ios_xe_software 16.12.1z
  - ios_xe_software 16.9.1a
published: '2026-08-05'
updated: '2026-08-06'
sourceUpdated: '2026-08-06T15:44:56.043'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20308'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-dos-qdc7qx3
    label: psirt@cisco.com
  - url: 'https://software.cisco.com'
tags:
  - nvd
  - cve.org
  - csaf
  - vendor-advisory
  - cisco
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-05T17:34:35.714176Z'
ingestedAt: '2026-09-12T16:30:47.528Z'
epss: 0.0032
epssPercentile: 0.223
---

## Overview

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device.

This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **cisco-sa-webui-dos-qdc7qx3** · Cisco · affected: Cisco Aironet Access Point Software (IOS XE Controller), Cisco IOS XE Catalyst SD-WAN, Cisco IOS XE Software (241 versions), Cisco IOS XE Software Bootloader (ROMMON), Cisco IOS XG Software, Cisco IOS XR Software · updated 2026-08-05 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-dos-qdc7qx3)
