CVE-2026-76412
largeAuthenticated Privilege Escalation to Root in Cisco Secure FMC Remote Diagnostics
CVE-2026-76412 is a privilege-escalation flaw (CWE-264) in the remote diagnostics debugger of Cisco Secure FMC (Firewall Management Center) Software, caused by an error when checking the privilege level of a user invoking remote diagnostics. An attacker who holds valid credentials on the device—no matter how low-privileged—can authenticate via the web-based management interface or the REST API and use the remote diagnostics debugger to enable the service and grant elevated privileges. A successful exploit elevates the attacker to root on the FMC, the central management platform for Cisco Secure Firewalls, giving full control over firewall management (scope-changing, with high confidentiality, integrity, and availability impact). Any organization running Cisco Secure FMC with user accounts is potentially affected, though attack complexity is high because exploitation requires valid credentials and a multistage process. No public proof-of-concept is known, exploitation has not been observed in the wild, and the flaw is not on the CISA KEV list.
What to do: Upgrade FMC to the fixed release specified in Cisco's security advisory for CVE-2026-76412 (exact version numbers are not provided in this dataset). Until patched, restrict access to the FMC web-based management interface and REST API to trusted management networks or a dedicated management interface, audit and remove unnecessary local user accounts, and monitor device logs for enabling or use of the remote diagnostics debugger service.
| Cisco Secure FMC (Firewall Management Center) Software | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote attacker to enable the remote diagnostics debugger service. This vulnerability is due to an error when checking the privilege level of a user who is invoking remote diagnostics. An attacker could exploit this vulnerability by authenticating to the device, either through the web-based management interface or the REST API, and using the remote diagnostics debugger to grant a user elevated privileges. A successful exploit could allow the attacker to elevate privileges to root. Notes: To exploit this vulnerability, the attacker must have valid user credentials on the affected device. The CVSSv3.1 Attack Complexity is High due to the multistage process required to fully exploit this vulnerability.
- Weakness
- CWE-264
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.