Cisco IOS XR Software Improper Access Control (CVE-2026-20279)

Release Date: 2nd September 2026

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, System/Network administrators, and telecommunications/Internet Service Provider network engineering teams that deploy or operate Cisco IOS XR Software on carrier-grade routing platforms. This alert is intended to be understood by technical users and systems administrators.

 

What is it?

CVE-2026-20279 is a critical improper access control vulnerability in Cisco IOS XR Software, Cisco's carrier-grade network operating system used on service-provider and enterprise core/edge routing platforms (including the ASR 9000 Series and other Cisco IOS XR-based routers). The vulnerability affects all releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration. It was identified by Cisco's own IOS XR engineering team as part of a comprehensive internal security review, and was disclosed together with six related CVEs (CVE-2026-20274 through CVE-2026-20278, and CVE-2026-20280) in the same Cisco IOS XR Software Security Hardening Release for September 2026 - this advisory covers CVE-2026-20279 specifically, the highest-severity issue in that release; organizations patching against it should be aware the same hardening release addresses the other six CVEs as well.

What are the systems affected?

The following version(s) are affected:

All releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration – (Affected)

Cisco has not released a single unified "fixed version" for this vulnerability - instead, fixes are delivered per software train as Security Maintenance Updates (SMUs) that must be applied on top of the existing release (for example, SMUs are available for 6.9.2, 7.3.2, 24.4.2, and 26.1.2, among other trains; some trains, such as 26.3, receive their fix directly in the upcoming 26.3.1 release). Cisco states that future Cisco IOS XR Software releases 26.2.2 and 26.3.1 will be the first fixed releases that do not require a separate SMU. Because the exact required SMU or fixed release depends on which train a given device is running, administrators should consult the fixed-release table in Cisco Security Advisory cisco-sa-hardening-iosxr-qg64NcM directly, or use Cisco's Software Checker tool, rather than relying on a single version number.

What does this mean?

 

Typical attack flow:

 

  1. Reach the affected access-control function on an exposed IOS XR device — An attacker sends a crafted request to a reachable Cisco IOS XR device — Cisco's advisory does not publish the specific vulnerable interface or protocol to avoid providing an exploitation roadmap, describing the underlying issue only in general terms as improper access control covering improper certificate validation, missing authentication, missing authorization, and incorrect authorization.
  2. Bypass the intended access control and gain unauthorized access — Because no authentication or user interaction is required (CVSS AV:N/AC:L/PR:N/UI:N), a successful attacker gains unauthorized access to functionality on the device that should have required proper authentication or authorization, with the potential for complete compromise of the device's confidentiality, integrity, and availability.

 

Mitigation process?

CERTVU recommends the following:

  1. Apply the Appropriate SMU or Fixed Release Without Delay

    Since Cisco has stated there is no workaround, identify the exact IOS XR software train running on each device and apply the corresponding SMU listed in Cisco Security Advisory cisco-sa-hardening-iosxr-qg64NcM (or use Cisco's Software Checker tool), or upgrade to a fixed release such as the upcoming 26.2.2 or 26.3.1 once available.
  2. Prioritize the SMU/Patch Rollout

    Since Cisco has confirmed there are no workarounds for this vulnerability, prioritize the SMU/patch rollout over any temporary compensating control.
  3. Audit the Estate for Cisco IOS XR Deployments

    Audit the estate for Cisco IOS XR deployments.
  4. Treat Unpatched Devices as Potentially Compromised

    Treat any internet-reachable, unpatched device as potentially compromised.
  5. Review Device Configuration and Access Logs

    Review device configuration and access logs.

Report suspected compromise to CERTVU at This email address is being protected from spambots. You need JavaScript enabled to view it. or on telephone (678) 33380.

 

 

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-20279
  2. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM