Cisco ThousandEyes Enterprise ... Note

Cisco ThousandEyes Enterprise Agent BrowserBot Command Injection Vulnerability

A vulnerability existed within the BrowserBot component of Cisco ThousandEyes Enterprise Agent, posing a security risk. This flaw could have enabled a remote attacker to execute arbitrary commands. The vulnerability stemmed from inadequate input validation of command arguments provided by the user. An attacker needed valid ThousandEyes SaaS credentials and test management capabilities to exploit this issue. Successful exploitation would have allowed command execution within the BrowserBot container. Cisco has since resolved this vulnerability within the ThousandEyes Enterprise Agent. No customer action is required to address this security issue. There are no available workarounds to mitigate the vulnerability. The security impact was rated as medium. This advisory is associated with CVE-2026-20206. The vulnerability allowed an authenticated attacker to potentially cause harm.