CVE-2026-20342
largeAuthenticated arbitrary file download in Cisco Secure FMC Software API
Cisco Secure FMC (the management center for Cisco Secure Firewall/Firepower deployments) contains a flaw in a specific file download API where user input is not sanitized, allowing arbitrary file downloads from the appliance. An authenticated, remote attacker can trigger it with a single crafted HTTPS request, provided they hold valid credentials for an account with at least the read-only Security Analyst role, so it is primarily an insider or compromised-account risk. A successful exploit exposes any file on the system, which on an FMC can include configuration data, certificates, and other secrets, with no impact on integrity or availability (CVSS 7.7, high confidentiality impact, scope changed). Any organization running Cisco Secure FMC Software is affected; the source data does not specify version ranges. As of now there is no known exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV catalog.
What to do: Upgrade FMC to a fixed release as specified in Cisco's security advisory, and in the meantime restrict access to the FMC web interface to trusted management networks. Audit which accounts hold the Security Analyst role or higher, since any such credential is sufficient to exploit, and monitor HTTPS traffic to file download API endpoints for requests containing unexpected file paths.
| Cisco Secure FMC Software (Secure Firewall Management Center, formerly Firepower Management Center) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability exists because user input is not being sanitized. An attacker could exploit this vulnerability by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from the affected system. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Security Analyst (read-only).
- Weakness
- CWE-639
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.