← Vulnerability feed

Vulnerability record · CVE-2020-26072 · published 18 November 2020

CVE-2020-26072: Cisco iot field network director improper access control vulnerability

Cisco · Iot Field Network Director

A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the SOAP API. An attacker could exploit this vulnerability by sending SOAP API requests to affected devices for devices that are outside their authorized domain. A successful exploit could allow the attacker to access and modify information on devices that belong to a different domain.

8.7 CVSS 3.1 High EPSS 1.0% · top 38.3% CWE-284 · Improper access controlCWE-269 · Improper privilege management
8.7CVSS 3.1 base score, v2 5.5
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the SOAP API. An attacker could exploit this vulnerability by sending SOAP API requests to affected devices for devices that are outside their authorized domain. A successful exploit could allow the attacker to access and modify information on devices that belong to a different domain.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-26072 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2020-3531Cisco iot field network director missing authentication for critical function vulnerabilityA vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end data…EPSS 2.2%8.8CVE-2020-26075Cisco iot field network director sql injection vulnerabilityA vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to gain access to the back-en…EPSS 1.6%8.8CVE-2018-0270Cisco iot field network director cross-site request forgery vulnerabilityA vulnerability in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker t…EPSS 0.68%7.7CVE-2026-20167Cisco iot field network director improper access control vulnerabilityA vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low priv…EPSS 0.27%7.5CVE-2020-3392Cisco iot field network director missing authentication for critical function vulnerabilityA vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on…EPSS 1.5%7.5CVE-2020-26076Cisco iot field network director information exposure vulnerabilityA vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive database information on a…EPSS 1.3%7.5CVE-2020-3162Cisco iot field network director improper input validation vulnerabilityA vulnerability in the Constrained Application Protocol (CoAP) implementation of Cisco IoT Field Network Director could allow an unauthenticated remo…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2020-26072), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.