GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco NX-OS: Python sandbox escape gives a low-privilege user shell access to the switch OS

CVSS 4.4CVE-2026-20032Firmware, BMC & network fabriccurated

Impact

The NX-OS Python interpreter is meant to confine scripted automation to a sandbox. Insufficient input validation lets an authenticated low-privilege user manipulate interpreter functions and execute arbitrary commands on the underlying operating system with that user's privileges. On a fabric switch this converts a read-mostly or restricted-role account - the kind handed to automation, monitoring or junior operators - into general-purpose access on a device that carries every tenant's traffic. It is not a direct jump to root: commands run as the authenticated user, and the vendor scores confidentiality and integrity as low.

Who can reach it

A local, authenticated user with low privileges on the switch who can invoke the embedded Python interpreter. Authentication is required; no network-only path is described.

What to do

Upgrade to a fixed NX-OS release per Cisco advisory cisco-sa-nxos-mppe-dhKZAFgb, which reloads the switch and so needs a per-device maintenance window. In the meantime, treat the Python interpreter as a privileged feature: review which roles can reach it and prune low-privilege accounts that do not need it. The record does not state a vendor workaround or specific fixed versions - read the advisory for those.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.