If exploited, these flaws could allow an authenticated, local attacker to execute arbitrary commands as root or gain full administrative control over affected routing devices.
Both vulnerabilities were discovered during internal security testing by Cisco, and the company has released official software updates to address the flaws.
The vulnerabilities operate independently, meaning an attacker does not need to exploit one to leverage the other.
CVE-2026-20040: Root Command Execution
Discovered by Tristan Van Egroo of Cisco’s Advanced Security Initiatives Group (ASIG), this vulnerability stems from insufficient validation of user arguments passed to specific Command-Line Interface (CLI) commands.
An attacker with a low-privileged account can exploit this flaw by inputting specially crafted commands at the prompt.
A successful exploit elevates the attacker’s privileges to root, allowing them to execute arbitrary commands directly on the underlying operating system.
CVE-2026-20046: Administrative Control Bypass
This secondary vulnerability arises from incorrect mapping of a CLI command to task groups in the software’s source code.
A low-privileged user can exploit this flaw using specific CLI commands to bypass task group-based checks.
Successful exploitation hands the attacker full administrative control of the device, completely bypassing standard authorization checks.
These vulnerabilities specifically target the IOS XR environment:
Cisco has explicitly confirmed that its IOS, IOS XE, and NX-OS software lines are not vulnerable to these exploits.
Cisco strongly recommends that network administrators upgrade to fixed software releases immediately. Software Maintenance Updates (SMUs) are also available for specific platforms.
Administrators should take the following actions:
According to the Cisco Product Security Incident Response Team (PSIRT), there are no known public exploits or malicious threat actor campaigns currently leveraging these vulnerabilities in the wild.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
The post Cisco IOS XR Software Vulnerability Allow Attacker to Execute Commands as Root appeared first on Cyber Security News.
Warning: This review contains full spoilers for The Pitt Season 2, Episode 10!The best episodes…
Apple recently released its newest budget smartphone - the Apple iPhone 17e - on March…
Blight: Survival has reemerged with a new gameplay trailer — and its developers are promising…
Bluetti is well known for its high quality yet affordable power stations and solar generators.…
There’s something endlessly endearing about a good-natured dummy. Just a happy, optimistic doofus that can…
(KTAB/KRBC) - The Sweetwater Rattlesnake Roundup Parade for 2026 is taking place at 4:30 p.m.,…
This website uses cookies.