CVE-2026-20038
Cisco Nexus 9000 Series Fabric Switches in ACI Mode Policy-Based Redirect Endpoint Group Contract Bypass Vulnerability
CVSS Score
5.8
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, remote attacker to bypass configured EPG contracts. This vulnerability is due to an improper control with EPG contracts. An attacker could exploit this vulnerability by sending IPv4 or IPv6 packets using UDP source and destination ports that are assigned to DHCP traffic through an affected device. A successful exploit could allow the attacker to bypass EPG contracts on the affected device.
| CWE | CWE-284 |
| Vendor | cisco |
| Product | cisco nx-os system software in aci mode |
| Ecosystems | |
| Industries | NetworkingTelecommunications |
| Published | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for cisco cisco nx-os system software in aci mode
Be the first to know when new medium vulnerabilities affecting cisco cisco nx-os system software in aci mode are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None
Affected Versions
Cisco / Cisco NX-OS System Software in ACI Mode
15.2(1g) 15.2(2e) 15.2(2f) 15.2(2g) 15.2(2h) 15.2(3f) 15.2(3e) 15.2(3g) 15.2(4d) 15.2(4e) 15.2(5c) 15.2(5d) 16.0(1g) 15.2(5e) 15.2(4f) 15.2(6e) 15.2(6h) 16.0(1j) 15.2(6g) 15.2(7f) 15.2(7g) 16.0(2h) 15.2(8d) 16.0(2j) 15.2(8e) 16.0(3d) 16.0(3e) 15.2(8f) 15.2(8g) 15.3(1d) 15.2(8h) 16.0(4c) 15.3(2a) 15.2(8i) 16.0(5h) 15.3(2b) 16.0(3g) 16.0(5j) 15.3(2c) 16.0(6c) 15.3(2d) 16.1(1f) 16.0(7e) 16.0(8e) 15.3(2e) 16.0(8f) 16.1(2f) 16.1(2g) 15.3(2f) 16.0(9c) 16.1(3f) 16.0(9d) 16.0(6h) 16.0(8h) 16.1(3g) 16.0(9e) 16.1(4h) 16.1(5e) 16.2(1g) 16.0(9f) 16.2(2e)