Cisco IOS XE Lobby Ambassador Privilege Escalation Vulnerability

Vulnerability

A vulnerability exists in the Lobby Ambassador web-based management API of Cisco IOS XE Software. It allows an authenticated, remote attacker to elevate privileges and access management APIs typically unavailable to Lobby Ambassador users. This issue arises because the API endpoint does not adequately validate received parameters. An attacker could exploit this by authenticating as a Lobby Ambassador user and sending a crafted HTTP request to an affected device. Successful exploitation could enable the attacker to create a new user with privilege level 1 access to the web-based management API, allowing access to the device with these new credentials and privileges.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a user to access restricted management APIs and functionalities.

Remediation

Cisco has released software updates to address this vulnerability. For guidance on upgrading to a fixed software release, consult the Cisco IOS and IOS XE Software Security Advisory Bundled Publication or use the Cisco Software Checker tool to identify the earliest release that fixes this vulnerability.

Added: Mar 25, 2026, 4:20 PM
Updated: Mar 25, 2026, 4:20 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
5.0
exploitability
4.9
remediation
0.0
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.