CVE-2026-20040 | Cisco IOS XR up to 25.4.1 CLI os command injection (cisco-sa-iosxr-privesc-bF8D5U4W / EUVD-2026-11214)
A vulnerability categorized as critical has been discovered in Cisco IOS XR. Affected is an unknown function of the component CLI. Executing a manipulation can lead to os command injection.
This vulnerability is registered as CVE-2026-20040. The attack needs to be launched locally. No exploit is available.
It is advisable to upgrade the affected component.