Vulnerabilities · 74 days ago

Catalyst Center File-Read Bug Exposes Local Secrets

A restricted container did not stop Catalyst Center from leaking files, so the broken assumption is that isolation alone contains a file-read bug. An attacker who can send a crafted HTTP request can step outside the intended directory and read local files without authenticating, which makes configs and stored secrets the real concern.

Cisco fixed CVE-2026-20191 in Catalyst Center and says there is no workaround. The issue affects the hardware appliance and virtual appliances on AWS, Azure, and VMware ESXi, and the advisory points to arbitrary file reads inside the limited container rather than broader code execution.

Even a narrow file-read flaw matters here because management-plane systems often keep credentials, tokens, and other sensitive local data on disk. That makes the platform a source of reusable trust, not just a single vulnerable service.

CVE-2026-20191

NVD KEV

CVSS 7.5 HIGH: a vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from… EPSS 0.9% (57th percentile).

Timeline

Sources

2 sources covering this story

Entities

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-07-03

Editions

Related stories