← Home
Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability
Source: cisco / cisco-sa-teva-os-command-W4GAO6jp
— original advisory
Published: 2026-09-16
· Last updated: 2026-09-16
· Vendor severity: Medium
CVEs
| CVE | CVSS | CWE | Exploitation |
| CVE-2026-20350 |
4.7 |
CWE-78: OS Command Injection |
Not observed in the wild |
Affected Products
| Product | Affected versions | Fixed version |
| Cisco ThousandEyes Endpoint Agent |
Not specified by vendor |
Not specified by vendor |
| Cisco ThousandEyes Enterprise Agent |
Not specified by vendor |
Not specified by vendor |