CVE Explorer
CVE-2026-20206
A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process. Cisco has addressed this vulnerability in the Cisco ThousandEyes Enterprise Agent, and no customer action is needed.
This vulnerability was due to insufficient input validation of command arguments that are supplied by the user. Prior to this vulnerability be
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"Cisco ThousandEyes Enterprise Agent","vendor":"Cisco","versions":[{"status":"affected","version":"Agent 5.0"},{"status":"affected","version":"Agent 4.4.4"},{"status":"affected","version":"Agent 4.4.3"},{"status":"affected","version":"Agent 4.4.2"},{"status":"affected","version":"Agent 4.2"},{"status":"affected","version":"Agent 4.1"},{"status":"affected","version":"Agent 4.0"},{"status":"affected","version":"Agent 5.1"},{"status":"affected","version":"Agent 5.1.2"},{"status":"affected","version":"Agent 5.1.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6b40ebbd900cc4b9c2f04e35ee4c4bb3250225ef6f737046eb4f1b28390082b4 · sha256:b8e2b6e2ba323448… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6b40ebbd900cc4b9c2f04e35ee4c4bb3250225ef6f737046eb4f1b28390082b4 · sha256:b8e2b6e2ba323448… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-78","description":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"cwe"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6b40ebbd900cc4b9c2f04e35ee4c4bb3250225ef6f737046eb4f1b28390082b4 · sha256:b8e2b6e2ba323448… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"cisco-sa-tebbot-cmdinj-wN3yQ5gn","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tebbot-cmdinj-wN3yQ5gn"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6b40ebbd900cc4b9c2f04e35ee4c4bb3250225ef6f737046eb4f1b28390082b4 · sha256:b8e2b6e2ba323448… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.