LiveActive security incident?Get immediate response
CVE Record

CVE-2020-26552: An issue was discovered in Aviatrix Controller before R6.0.2483.

An issue was discovered in Aviatrix Controller before R6.0.2483. Multiple executable files, that implement API endpoints, do not require a valid session ID for access.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Aviatrix Controller before R6.0.2483 exposed multiple API endpoint executables without requiring a valid session. In business terms, some controller functions could be reachable without normal login checks. The sources do not provide CVSS, affected endpoint names, or confirmed exploitation.

Executive priority

Prioritize remediation for any exposed Aviatrix Controller older than R6.0.2483. Treat internal-only instances as important but lower urgency, depending on segmentation. The lack of public exploitation evidence reduces emergency pressure but does not remove risk.

Technical view

CVE-2020-26552 is an authentication enforcement flaw in Aviatrix Controller before R6.0.2483. Multiple executable files implementing API endpoints did not require a valid session ID. Public data is sparse: no CWE, CVSS, endpoint list, or vendor remediation details beyond the fixed-version boundary are included in the supplied sources.

Likely exposure

Exposure is likely limited to organizations running Aviatrix Controller versions before R6.0.2483. Risk is higher where the controller management interface or API endpoints are reachable from untrusted networks. The source bundle does not identify cloud deployments, appliances, or downstream products beyond Aviatrix Controller.

Exploitation context

The CVE is not listed as KEV, and the supplied sources do not claim active exploitation. The vulnerability class is still serious because unauthenticated access to controller API functionality can bypass expected administrative session controls.

Researcher notes

The supplied record lacks CVSS, CWE mapping, endpoint names, and exploit evidence. Analysis should stay anchored to authentication bypass on API endpoint executables in Aviatrix Controller before R6.0.2483. Do not assume remote code execution, privilege level, or endpoint behavior without additional vendor evidence.

Mitigation direction

  • Identify all Aviatrix Controller instances and record their versions.
  • Upgrade controllers before R6.0.2483 to R6.0.2483 or later where supported.
  • Restrict controller management and API access to trusted administrative networks.
  • Review Aviatrix and Critical Start guidance for any product-specific remediation details.
  • Monitor controller logs for suspicious unauthenticated API access patterns.

Validation and detection

  • Confirm every controller reports version R6.0.2483 or later.
  • Verify management and API endpoints are not internet-exposed unless explicitly required.
  • Review access logs around API executables for requests lacking valid sessions.
  • Check vulnerability scanners or asset inventory for CVE-2020-26552 findings.
  • Document any remaining legacy controller exposure and compensating controls.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-26552 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.