CVE-2026-20161
Cisco ThousandEyes Enterprise Agent Arbitrary File Overwrite Vulnerability
Description
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low privileges to overwrite arbitrary files on the local system of an affected device. This vulnerability is due to improper access controls on files that are on the local file system of an affected device. An attacker could exploit this vulnerability by placing a symbolic link in a specific location on the local file system. A successful exploit could allow the attacker to bypass file system permissions and overwrite arbitrary files on the affected device.
Weakness: CWE-59
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco ThousandEyes | Network & Security Management | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco ThousandEyes Enterprise Agent
Vendor advisory
cisco-sa-te-agentfilewrite-tqUw3SMU
Cisco ThousandEyes Enterprise Agent Arbitrary File Overwrite Vulnerability
Cisco’s rating: Medium (advisory CVSS 5.5) · Published Apr 15, 2026
Bug ID: CSCwt47572
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from