CVE-2026-20206

MEDIUM

A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the Brow...

Affects 0 products across 4 vendors.

BCS4.37
CVSS 3.16.3
EPSS0.4%
Percentile34th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component.
CWE Weakness Definitions
CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-78
CAPEC-108 Command Line Execution through SQL Injection
via CWE-78
CAPEC-6 Argument Injection
via CWE-78
CAPEC-15 Command Delimiters
via CWE-78
CAPEC-88 OS Command Injection
via CWE-78

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A medium severity vulnerability affects Cisco systems (CVE-2026-20206). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.

BSID: BS-2026-GLOBAL-063255-M • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-20206?
A medium severity vulnerability affects Cisco systems (CVE-2026-20206). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.
What is the CVSS score for CVE-2026-20206?
CVE-2026-20206 has CVSS 6.3 (Medium). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L. EPSS: 0.4%.
Is CVE-2026-20206 actively exploited?
No confirmed active exploitation of CVE-2026-20206 as of 2026-07-24.
How do I remediate CVE-2026-20206?
Priority: LOW. Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tebbot-cmdinj-wN3yQ5gn PSIRT: [email protected]
What systems are affected by CVE-2026-20206?
CVE-2026-20206 affects: Cisco, Francisco Burzi, Saas, Valid.
Vulnerability Details
CVE IDCVE-2026-20206
BSIDBS-2026-GLOBAL-063255-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Published2026-05-20
Last Modified2026-07-23
ICS Relevance70%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process. Cisco has addressed this vulnerability in the Cisco ThousandEyes Enterprise Agent, and no customer action is needed. This vulnerability was due to insufficient input validation of command arguments that are supplied by the user. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by authenticating to the ThousandEyes SaaS and submitting crafted input into the affected parameter. A successful exploit could have allowed the attacker to execute arbitrary commands within the BrowserBot container as the node user. To exploit this vulnerability, the attacker must have valid user credentials for the ThousandEyes SaaS and the ability to manage transaction tests.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process. Cisco has addressed this vulnerability in the Cisco ThousandEyes Enterprise Agent, and no customer action is needed. This vulnerability was due to insufficient input validation of command arguments that are supplied by the user. Prior to this vulnerability be CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L.

Exploitation Likelihood: MINIMAL

Affected Products
VendorProductFixed Version
Cisco —
Francisco Burzi —
Saas —
Valid —
Remediation
View Vendor Advisory →

Remediation Priority: LOW

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 66 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashf52709170e8bd16b28b3ce35a88b7a2278e757705b4065a5659aa3f5b9e199be0eab4f297b9f01964c252412fd9886ca389b15f8c5f9085253785d5f6760b0e9
Related CVEs affecting Cisco
CVE-2025-20393 10.0 A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for ... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2003-0732 10.0 CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the gues... CVE-2004-0308 10.0 Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(... CVE-2007-5382 10.0 The conversion utility for converting CiscoWorks Wireless LAN Solution Engine...
View all Cisco CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →