AI analysis
CVE-2026-20328 is a critical missing-authorization flaw (CWE-862) in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem). Improper checks during password reset let an unauthenticated remote attacker send a crafted request and reset the password of an arbitrary account, including high-privileged administrators. A successful attack yields unauthorized access as that user, with high impact to confidentiality and integrity and no availability impact (CVSS 3.1 9.1). Organizations running this on-premises Cisco license-management application are affected; specific version ranges were not included in the supplied data. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Treat the web management interface as untrusted until Cisco’s fix is applied: do not expose it to the internet, restrict it to trusted admin networks, and install the vendor patch as soon as Cisco publishes fixed releases for your build. Review admin and user accounts for unexpected password resets or logins, and rotate credentials for privileged accounts if compromise is suspected. Follow the Cisco PSIRT advisory for this CVE for the exact fixed versions rather than guessing a release number.
Affected
| Cisco License On-Prem (formerly Cisco Smart Software Manager On-Prem / SSM On-Prem) | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to gain unauthorized access to an affected application. This vulnerability is due to improper checks during the password reset process. An attacker could exploit this vulnerability by sending a malicious request to the web-based management interface. A successful exploit could allow the attacker to reset the password of an arbitrary account, including high-privileged administrative user accounts, possibly allowing the attacker to gain unauthorized access to the application as any user.