CVE-2026-20344
moderateAuthenticated SQL Injection in Cisco Secure FMC Web Management Interface
A SQL injection vulnerability (CWE-89) in the web-based management interface of Cisco Secure FMC Software is caused by insufficient validation of user-supplied input. To trigger it, an attacker must already hold a valid account on the device with the Security Approver, Access Admin, or Network Admin role and send a crafted HTTP request to the management interface. A successful exploit allows the attacker to read any data from the database, obtain the session credentials of an authenticated Administrator, and then take actions with administrative privileges on the affected device, effectively escalating a limited role to full admin control. Organizations running Cisco Secure FMC to manage their Cisco Secure Firewall estates are potentially affected. As of this writing, the flaw is not in the CISA KEV catalog and no public proof-of-concept or confirmed in-the-wild exploitation is known.
What to do: Upgrade Cisco Secure FMC to the fixed release identified in Cisco's security advisory (fixed version numbers are not included in the available data). Until patched, restrict access to the FMC web management interface to trusted management networks and audit accounts holding the Security Approver, Access Admin, or Network Admin roles. Because successful attacks can harvest administrator session credentials, consider rotating admin passwords and invalidating active sessions on unpatched devices.
| Cisco Secure FMC Software (web-based management interface) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to perform a SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have a valid account on the device with the role of Security Approver, Access Admin, or Network Admin. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain any data from the database, obtain the session credentials of an authenticated Administrator, and take actions with administrative privileges on the affected device.
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.