Cisco IOS XR Vulnerability Exposes Systems to Root Command Execution by Attackers
Cisco has released critical software updates to address two high-severity privilege escalation vulnerabilities in its IOS XR Software. These vulnerabilities could allow an authenticated, local attacker to execute arbitrary commands as the root user or…
Cisco has released critical software updates to address two high-severity privilege escalation vulnerabilities in its IOS XR Software. These vulnerabilities could allow an authenticated, local attacker to execute arbitrary commands as the root user or gain complete administrative control over affected devices.
The vulnerabilities are identified as CVE-2026-20040 and CVE-2026-20046, each with a CVSS base score of 8.8 out of 10. They do not require chaining for a successful exploit.
CVE-2026-20040: A Command-Line Interface (CLI) privilege escalation flaw due to improper validation of user arguments in specific CLI commands, potentially allowing privilege elevation. CVE-2026-20046: A CLI privilege escalation issue specific to Cisco IOS XRv 9000 Routers caused by incorrect CLI command mapping, allowing bypass of task-group-based security checks.
Cisco confirmed that other operating systems, including standard IOS Software, IOS XE Software, and NX-OS Software, are not affected by these vulnerabilities.
Cisco has released critical software updates to address two high-severity privilege escalation vulnerabilities in its IOS XR Software.
Administrators are strongly advised to upgrade affected systems to the latest fixed software releases. The recommended actions differ slightly for each vulnerability:
CVE-2026-20040: Patching is mandatory, as no workarounds are available. Administrators should apply the provided software updates or Software Maintenance Updates (SMUs). CVE-2026-20046: A workaround exists for devices using TACACS+ authentication, authorization, and accounting (AAA) command authorization. This can restrict command access for non-administrative users.
New software versions, such as 25.2.21 and 25.4.2, include security patches. Administrators running older versions, like 25.1 or those on the 25.3 release branch, should migrate to a fixed release immediately. SMUs are available to facilitate rapid patching without a full system upgrade.
Based on reporting by GBHackers.
