Review reviewHigh

CVE-2026-20046

Cisco Cisco IOS XR Software, ios xr, ios xrv 9000

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerability is due to incorrect mapping of a command to task groups within the source code. An attacker with a low-privileged account could exploit this vulnerability by using the CLI command to bypass the task group–based checks. A successful exploit could allow the attacker to elevate privileges and perform actions on an affected device without authorization c...

CVSS
8.8
EPSS
0.14%
3.39% percentile
CISA KEV
Not listed
Published
2026.03.12
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.14%
Technical severityCVSS 8.8

Vulnerability overview

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerability is due to incorrect mapping of a command to task groups within the source code. An attacker with a low-privileged account could exploit this vulnerability by using the CLI command to bypass the task group–based checks. A successful exploit could allow the attacker to elevate privileges and perform actions on an affected device without authorization c...

Affected product and versions

Product
Cisco Cisco IOS XR Software, ios xr, ios xrv 9000
Affected versions
6.6.1, 6.5.3, 7.0.1, 6.5.1, 6.5.2, 6.6.2, 6.6.25, 7.1.1, 7.0.90, 6.6.3, 7.0.2, 7.1.2, 7.2.1, 6.6.4, 7.3.1, 7.4.1, 7.2.2, 7.3.2, 7.5.1, 7.6.1
Fixed versions
25.2.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Cisco Cisco IOS XR Software, ios xr, ios xrv 9000 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-264
CVE-2026-20046 — Cisco Cisco IOS XR Software, ios xr, ios xrv 9000 | SECUFOCUS NOW