CVE-2026-20350 PUBLISHED

Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability

Assigner: cisco
Reserved: 08.10.2025 Published: 16.09.2026 Updated: 16.09.2026

A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands.

This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by saving configuration details that contain malicious values. A successful exploit could allow the attacker to execute arbitrary operating system commands with root privileges. To exploit this vulnerability, the attacker must have valid administrative credentials.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 4.7

Product Status

Vendor Cisco
Product Cisco ThousandEyes Enterprise Agent
Versions Default: unknown
  • Version Agent 5.0 is affected
  • Version Agent 4.4.4 is affected
  • Version Agent 4.4.3 is affected
  • Version Agent 4.4.2 is affected
  • Version Agent 4.2 is affected
  • Version Agent 4.1 is affected
  • Version Agent 4.0 is affected
  • Version Agent 5.1 is affected
  • Version Agent 5.1.2 is affected
  • Version Agent 5.1.3 is affected
  • Version Agent 5.2.0 is affected

Exploits

The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.

References

Problem Types

  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') cwe