CVE-2026-20191: Cisco Catalyst Center

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.

Affected products

  • Cisco Catalyst Center: from 2.3.7.0, up to and including 2.3.7.11; from 3.1.3, before 3.1.6-75524.200 (fixed in 3.1.6-75524.200)
  • Cisco Catalyst Center Global Manager: before 1.4.1 (fixed in 1.4.1)

Published 2026-07-01. Last modified 2026-09-17.