Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
embedded-device-vulnerabilitywidely-deployed-product-advisorycredential-access-method

Cisco IOS XR CLI Privilege Escalation Vulnerabilities Enabling Root Command Execution

Updated 2mo agoFirst seen Mar 12, 20263 sources

Cisco released fixes for two high-severity privilege-escalation vulnerabilities in Cisco IOS XR Software that could allow an authenticated, local, low-privileged user to elevate privileges and either execute arbitrary commands as root or obtain full administrative control of affected routing devices. The issues were identified during Cisco internal testing and are described as independent flaws (exploitation of one is not required to exploit the other); Cisco provided software updates to remediate affected versions.

One flaw, CVE-2026-20040, is caused by insufficient validation of user-supplied arguments to certain CLI commands, enabling crafted input to result in root-level command execution. The second, CVE-2026-20046, stems from incorrect mapping of a CLI command to task groups, allowing bypass of task-group authorization checks and granting administrative control; it specifically impacts IOS XRv 9000. Canada’s Centre for Cyber Security highlighted Cisco’s broader advisory set (AV26-223), which includes these IOS XR CLI privilege escalation vulnerabilities alongside other IOS XR denial-of-service issues and web vulnerabilities in Cisco contact center products, and urged organizations to apply vendor updates as they become available.

Share:
Cisco IOS XR CLI Privilege Escalation Vulnerabilities Enabling Root Command Execution
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Mar 11, 20263mo ago

Canadian Centre for Cyber Security urges users to apply Cisco mitigations

Following Cisco's advisory release, the Canadian Centre for Cyber Security published alert AV26-223 advising administrators to review Cisco's notices, follow recommended mitigations, and apply updates when available. The alert highlighted affected Cisco IOS XR, NCS 5700, and contact center products.

Cisco discloses IOS XR privilege-escalation flaws and releases fixes

Cisco disclosed CVE-2026-20040 and CVE-2026-20046 in Cisco IOS XR Software, describing how an authenticated local attacker could gain root command execution or full administrative control on affected devices. Cisco released software updates and some SMUs, said no workaround exists for CVE-2026-20040, and reported no known public exploitation or in-the-wild abuse at disclosure time.

Cisco publishes multiple security advisories across product lines

On 2026-03-11, Cisco released multiple advisories covering vulnerabilities in Cisco NCS 5700 hardware platforms, Cisco IOS XR Software, and several Cisco contact center products. The issues included denial-of-service flaws, CLI privilege-escalation vulnerabilities, and cross-site scripting weaknesses.

Apr 15, 20215y ago

Cisco patches IOS XRv command injection flaw CVE-2021-1485

Cisco released a vendor patch for CVE-2021-1485, a command injection vulnerability in Cisco IOS XRv 64-bit that allowed an authenticated CLI user to inject arbitrary commands via improperly quoted router CLI commands. The issue affected commands such as dir, mkdir, more, and delete, and could lead to root-level compromise of the underlying operating system.

(CVE-2021-1485) Cisco IOS XR CLI Arbitrary Command Injection | STAR Labs
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

4 LINKEDOpen in app
Affected products
1 linked
Cisco Ios
Organizations
1 linked
Cisco Systems
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.