CVE-2026-20114 | Cisco IOS XE up to 17.18.1w Lobby Ambassador Web-based Management API improper validation of syntactic correctness of input (cisco-sa-iosxe-lobby-privesc-KwxBqJy / EUVD-2026-15445)
A vulnerability classified as critical has been found in Cisco IOS XE. Affected by this vulnerability is an unknown functionality of the component Lobby Ambassador Web-based Management API. The manipulation leads to improper validation of syntactic correctness of input.
This vulnerability is uniquely identified as CVE-2026-20114. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.