Catalyst Center File-Read Bug Exposes Local Secrets
A restricted container did not stop Catalyst Center from leaking files, so the broken assumption is that isolation alone contains a file-read bug. An attacker who can send a crafted HTTP request can step outside the intended directory and read local files without authenticating, which makes configs and stored secrets the real concern.
Cisco fixed CVE-2026-20191 in Catalyst Center and says there is no workaround. The issue affects the hardware appliance and virtual appliances on AWS, Azure, and VMware ESXi, and the advisory points to arbitrary file reads inside the limited container rather than broader code execution.
Even a narrow file-read flaw matters here because management-plane systems often keep credentials, tokens, and other sensitive local data on disk. That makes the platform a source of reusable trust, not just a single vulnerable service.