Directory Traversal Vulnerability in Cisco Secure Firewall Management Center Software
CVE-2026-20018
5.9MEDIUM
What is CVE-2026-20018?
A vulnerability in the sftunnel functionality of Cisco Secure Firewall Management Center and Threat Defense Software arises from inadequate validation of directory paths during file synchronization. This weakness allows an authenticated attacker with administrative access to craft malicious directory paths, potentially resulting in unauthorized file creation or replacement on the operating system. The implications of this vulnerability can be severe, as it may enable attackers to manipulate critical system files, leading to compromises of system integrity and security.
Affected Version(s)
Cisco Secure Firewall Management Center (FMC) 7.0.0
Cisco Secure Firewall Management Center (FMC) 7.0.0.1
Cisco Secure Firewall Management Center (FMC) 7.0.1