📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global supply_chain Software Development and Technology CRITICAL 57m Global data_breach Multiple Sectors HIGH 1h Global vulnerability Consumer Electronics / Mobile Devices CRITICAL 2h Global phishing Cybersecurity / Network Security CRITICAL 2h Global malware Critical Infrastructure / Government HIGH 2h Global supply_chain Cybersecurity / Software Supply Chain CRITICAL 3h Global general Multiple sectors MEDIUM 5h Global general Multiple sectors MEDIUM 5h Global malware Information Technology and Telecommunications HIGH 5h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 6h Global supply_chain Software Development and Technology CRITICAL 57m Global data_breach Multiple Sectors HIGH 1h Global vulnerability Consumer Electronics / Mobile Devices CRITICAL 2h Global phishing Cybersecurity / Network Security CRITICAL 2h Global malware Critical Infrastructure / Government HIGH 2h Global supply_chain Cybersecurity / Software Supply Chain CRITICAL 3h Global general Multiple sectors MEDIUM 5h Global general Multiple sectors MEDIUM 5h Global malware Information Technology and Telecommunications HIGH 5h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 6h Global supply_chain Software Development and Technology CRITICAL 57m Global data_breach Multiple Sectors HIGH 1h Global vulnerability Consumer Electronics / Mobile Devices CRITICAL 2h Global phishing Cybersecurity / Network Security CRITICAL 2h Global malware Critical Infrastructure / Government HIGH 2h Global supply_chain Cybersecurity / Software Supply Chain CRITICAL 3h Global general Multiple sectors MEDIUM 5h Global general Multiple sectors MEDIUM 5h Global malware Information Technology and Telecommunications HIGH 5h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 6h
Vulnerabilities

CVE-2026-20114

Medium
A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that woul
CWE-1286 — Weakness Type
Published: Mar 25, 2026  ·  Modified: Mar 28, 2026  ·  Source: NVD
CVSS v3
5.4
🔗 NVD Official
📄 Description (English)

A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby Ambassador users.

This vulnerability exists because parameters that are received by an API endpoint are not sufficiently validated. An attacker could exploit this vulnerability by authenticating as a Lobby Ambassador user and sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to create a new user with privilege level 1 access to the web-based management API. The attacker would then be able to access the device with these new credentials and privileges.

🤖 AI Executive Summary

CVE-2026-20114 is a privilege escalation vulnerability in Cisco IOS XE's Lobby Ambassador web-based management API that allows authenticated users to bypass access controls and create administrative accounts. While the CVSS score is moderate (5.4), the ability to escalate from limited Lobby Ambassador privileges to full management access poses significant risk to network infrastructure. No patch is currently available, requiring immediate compensating controls.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 26, 2026 12:40
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability directly impacts Saudi organizations operating Cisco IOS XE network infrastructure, particularly: (1) Banking sector (SAMA-regulated institutions) relying on Cisco equipment for critical network management; (2) Government agencies (NCA oversight) using Cisco infrastructure for secure communications; (3) Telecommunications providers (STC, Mobily) managing network access; (4) Energy sector (ARAMCO, utilities) operating industrial control networks. The ability to create privileged accounts threatens confidentiality, integrity, and availability of critical infrastructure. Organizations with Lobby Ambassador deployments face immediate risk of unauthorized administrative access.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Telecommunications Energy and Utilities Healthcare Critical Infrastructure
⚖️ Saudi Risk Score (AI)
7.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all Cisco IOS XE devices with Lobby Ambassador feature enabled using network inventory tools
2. Restrict network access to Lobby Ambassador API endpoints using firewall rules (limit to authorized administrative networks only)
3. Disable Lobby Ambassador feature if not operationally required
4. Implement strict authentication controls: enforce strong passwords (minimum 16 characters), enable MFA where supported
5. Monitor API logs for suspicious authentication attempts and user creation events

DETECTION RULES:
- Alert on HTTP requests to Lobby Ambassador API endpoints with parameter manipulation attempts
- Monitor for new user account creation via API with privilege level 1 access
- Track failed authentication attempts followed by successful API calls from same source IP
- Log all API endpoint access and review for anomalous patterns

COMPENSATING CONTROLS:
- Implement network segmentation isolating management interfaces
- Deploy IDS/IPS signatures detecting Lobby Ambassador API exploitation attempts
- Enable comprehensive audit logging on all Cisco devices
- Conduct weekly manual reviews of user accounts and access privileges
- Implement API rate limiting to prevent brute force attacks
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع أجهزة Cisco IOS XE مع تفعيل ميزة Lobby Ambassador باستخدام أدوات جرد الشبكة
2. تقييد الوصول إلى نقاط نهاية واجهة برمجة تطبيقات Lobby Ambassador باستخدام قواعد جدار الحماية (تقصير على الشبكات الإدارية المصرح بها فقط)
3. تعطيل ميزة Lobby Ambassador إذا لم تكن مطلوبة تشغيلياً
4. تطبيق عناصر تحكم مصادقة صارمة: فرض كلمات مرور قوية (16 حرفاً على الأقل)، تفعيل المصادقة متعددة العوامل حيث يكون مدعوماً
5. مراقبة سجلات واجهة برمجة التطبيقات للكشف عن محاولات مصادقة مريبة وأحداث إنشاء المستخدمين

قواعد الكشف:
- تنبيهات على طلبات HTTP إلى نقاط نهاية واجهة برمجة تطبيقات Lobby Ambassador مع محاولات معالجة المعاملات
- مراقبة إنشاء حسابات مستخدمين جديدة عبر واجهة برمجة التطبيقات بمستوى امتياز 1
- تتبع محاولات المصادقة الفاشلة متبوعة بنداءات واجهة برمجة التطبيقات الناجحة من نفس عنوان IP المصدر
- تسجيل جميع عمليات الوصول إلى نقاط نهاية واجهة برمجة التطبيقات ومراجعة الأنماط الشاذة

عناصر التحكم التعويضية:
- تطبيق تقسيم الشبكة لعزل واجهات الإدارة
- نشر توقيعات IDS/IPS للكشف عن محاولات استغلال واجهة برمجة تطبيقات Lobby Ambassador
- تفعيل تسجيل التدقيق الشامل على جميع أجهزة Cisco
- إجراء مراجعات يدوية أسبوعية لحسابات المستخدمين وامتيازات الوصول
- تطبيق تحديد معدل واجهة برمجة التطبيقات لمنع هجمات القوة الغاشمة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Access Control Policy ECC 2024 A.5.2.1 - User Registration and De-registration ECC 2024 A.5.3.1 - Access Rights Review ECC 2024 A.8.2.1 - User Access Management ECC 2024 A.8.3.1 - Management of Privileged Access Rights
🔵 SAMA CSF
SAMA CSF ID.AM-1 - Asset Management SAMA CSF PR.AC-1 - Access Control Policy SAMA CSF PR.AC-4 - Access Rights Management SAMA CSF DE.CM-1 - Network Monitoring SAMA CSF DE.AE-1 - Anomalies and Events Detection
🟡 ISO 27001:2022
ISO 27001:2022 A.5.2 - Information Security Policies ISO 27001:2022 A.8.2 - User Access Management ISO 27001:2022 A.8.3 - User Responsibilities ISO 27001:2022 A.9.2 - User Access Provisioning ISO 27001:2022 A.9.4 - Access Rights Review
📊 CVSS Score
5.4
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score5.4
CWECWE-1286
Exploit No
Patch ✗ No
Published 2026-03-25
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
7.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-1286
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.