PT-2026-21940 · Cisco · Cisco Application Policy Infrastructure Controller

·

CVE-2026-20107

·

Published

2026-02-25

·

Updated

2026-02-28

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Application Policy Infrastructure Controller (APIC) (affected versions not specified)
Description A flaw exists in the Object Model CLI component that may allow an authenticated, local attacker to trigger an unexpected reload of the device, leading to a denial of service (DoS). The issue stems from inadequate input validation. An attacker can exploit this by submitting specially crafted commands through the CLI prompt. The attacker must possess valid user credentials and a role with CLI access to succeed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-20107

Affected Products

Cisco Application Policy Infrastructure Controller