GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco NX-OS: crafted HTTP request to NX-API yields unauthenticated root code execution

CVSS 9.8CVE-2026-76471Firmware, BMC & network fabriccurated

Impact

NX-API is the programmatic management interface that automation and config-management tooling drives. Insufficient input validation on data sent to it lets an unauthenticated attacker who can reach that HTTP endpoint run code as root on the switch, or crash the process and trigger a device reload. On a GPU fleet this is the management-plane path: whoever holds root on the switch controls the data plane the cluster depends on, and the same advisory lists Cisco UCS (Managed) among the affected products, which puts compute management in the same blast radius. Note this is a separate flaw from the MPLS OAM issue published the same day - different feature, different advisory, different reach - and it is exposed to anything that can speak HTTP to the device rather than to IP packets alone.

Who can reach it

Anyone with HTTP access to the NX-API endpoint - in practice anyone on the management VLAN, or further afield if NX-API is reachable beyond it. No authentication required. Devices with the NX-API feature disabled are not exposed.

What to do

Upgrade to a fixed NX-OS release per the Cisco advisory; the advisory is authoritative for the per-platform fixed versions, so verify yours there. The upgrade reloads the switch, so plan it rack by rack and keep a spine path up. Until then, the practical mitigation is the feature itself: NX-API is off by default on most platforms, so check whether it is enabled (show feature | include nxapi) and disable it where automation does not need it. Where it is needed, restrict access to the management network with ACLs and front it so arbitrary hosts cannot reach the HTTP endpoint.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.