Cisco IOS XR Software Vulnerability Allow Attacker to Execute Commands as Root
Cisco has released a high-severity security advisory concerning two critical privilege-escalation vulnerabilities in its IOS XR Software. These vulnerabilities allow an authenticated, local attacker to execute arbitrary commands as root or gain full…
Cisco has released a high-severity security advisory concerning two critical privilege-escalation vulnerabilities in its IOS XR Software. These vulnerabilities allow an authenticated, local attacker to execute arbitrary commands as root or gain full administrative control over affected routing devices.
The vulnerabilities were identified during internal security testing by Cisco, and official software updates have been issued to address these issues. The vulnerabilities operate independently, so an attacker does not need to exploit one to leverage the other.
This vulnerability, discovered by Tristan Van Egroo of Cisco's Advanced Security Initiatives Group (ASIG), is due to insufficient validation of user arguments passed to specific Command-Line Interface (CLI) commands. An attacker with a low-privileged account can exploit this by inputting specially crafted commands at the prompt. A successful exploit elevates the attacker's privileges to root, enabling execution of arbitrary commands on the operating system.
CVE-2026-20046: Administrative Control Bypass
This secondary vulnerability arises from incorrect mapping of a CLI command to task groups in the software's source code. A low-privileged user can exploit this flaw using specific CLI commands to bypass task group-based checks, achieving full administrative control of the device and bypassing standard authorization checks.
Cisco has released a high-severity security advisory concerning two critical privilege-escalation vulnerabilities in its IOS XR Software.
These vulnerabilities specifically affect the IOS XR environment:
CVE-2026-20040 affects Cisco IOS XR Software across all device configurations. CVE-2026-20046 impacts Cisco IOS XRv 9000 Routers, regardless of configuration.
Cisco confirms that its IOS, IOS XE, and NX-OS software lines are not vulnerable to these exploits.
Cisco recommends upgrading to fixed software releases immediately. Software Maintenance Updates (SMUs) are available for specific platforms.
Administrators should consider the following actions:
Upgrade Firmware: Move affected systems to the latest fixed release (e.g., 25.2.21 or 25.4.2) as per the official advisory. Apply Workarounds (CVE-2026-20046 Only): For devices using TACACS+ authentication, authorization, and accounting (AAA), configure command authorization to restrict access, allowing non-administrative users access only to necessary commands. Prioritize CVE-2026-20040: No workarounds are available for this vulnerability, so immediate software upgrade is necessary.
The Cisco Product Security Incident Response Team (PSIRT) reports no known public exploits or active malicious campaigns using these vulnerabilities at this time.
Based on reporting by Cyber Security News.
