ZeroHour

CVE-2026-20342

large

Authenticated arbitrary file download in Cisco Secure FMC Software API

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

Cisco Secure FMC (the management center for Cisco Secure Firewall/Firepower deployments) contains a flaw in a specific file download API where user input is not sanitized, allowing arbitrary file downloads from the appliance. An authenticated, remote attacker can trigger it with a single crafted HTTPS request, provided they hold valid credentials for an account with at least the read-only Security Analyst role, so it is primarily an insider or compromised-account risk. A successful exploit exposes any file on the system, which on an FMC can include configuration data, certificates, and other secrets, with no impact on integrity or availability (CVSS 7.7, high confidentiality impact, scope changed). Any organization running Cisco Secure FMC Software is affected; the source data does not specify version ranges. As of now there is no known exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV catalog.

What to do: Upgrade FMC to a fixed release as specified in Cisco's security advisory, and in the meantime restrict access to the FMC web interface to trusted management networks. Audit which accounts hold the Security Analyst role or higher, since any such credential is sufficient to exploit, and monitor HTTPS traffic to file download API endpoints for requests containing unexpected file paths.

Affected
Cisco Secure FMC Software (Secure Firewall Management Center, formerly Firepower Management Center)
Estimated exposure
largetens of thousands of FMC deployments worldwide (internet-facing FMC consoles are a smaller subset, likely in the low thousands) — FMC is the standard management center deployed once per Cisco Secure Firewall/Firepower estate, giving a global installed base on the order of tens of thousands, while public scan data typically shows only a small fraction of these…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability exists because user input is not being sanitized. An attacker could exploit this vulnerability by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from the affected system. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Security Analyst (read-only).

Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.