Cisco Catalyst Center Arbitrary File Read Vulnerability

MonitorCVSS 7.5cisco-sa-catc-file-read-wLH2vf8XJul 1, 2026
Cisco
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A vulnerability in Cisco Catalyst Center allows an unauthenticated remote attacker to read arbitrary files from a restricted container due to insufficient validation of user-supplied input. An attacker can send a crafted HTTP request to the affected device to access sensitive files without needing credentials or authentication. Cisco has released software updates to address this vulnerability. No workarounds are available.

What this means
What could happen
An attacker could read sensitive files from Catalyst Center's container without needing any credentials, potentially exposing configuration data, credentials, or operational information used to manage your network infrastructure.
Who's at risk
Network operations teams and IT administrators who manage Cisco Catalyst Center for network device management and orchestration. The vulnerability affects all versions of Catalyst Center running on-premise or in cloud deployments.
How it could be exploited
An attacker sends a crafted HTTP request over the network to the Catalyst Center device. The vulnerability allows the request to bypass file access controls and read arbitrary files from the restricted container, with no authentication required.
Prerequisites
  • Network access to the Catalyst Center HTTP service (typically port 8080 or 443)
  • Ability to send HTTP requests to an affected device
remotely exploitableno authentication requiredlow complexityaffects network management system
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (1)
ProductAffected VersionsFix Status
Catalyst CenterAll versionsFix available
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Cisco Catalyst Center to the patched version released by Cisco
API: /api/v1/advisories/36cf8587-c472-4fce-82fa-c7f81c419b1c

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Cisco Catalyst Center Arbitrary File Read Vulnerability | CVSS 7.5 - OTPulse