Back to overview

CVE-2026-20079

CRITICAL
10.0
CVSS 3.1
Description
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.

Metadata

CVE ID
CVE-2026-20079
State
PUBLISHED
Assigner
cisco
Reserved
2025-10-08 11:59 UTC
Published
2026-03-04 17:17 UTC
Last updated
2026-03-05 14:06 UTC
Primary CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel
Vendor / Product
Cisco / Cisco Secure Firewall Management Center (FMC)
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Cisco Cisco Secure Firewall Management Center (FMC) 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1 …
Weakness (CWE)
CWESourceDescription
CWE-288 cna Authentication Bypass Using an Alternate Path or Channel
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview