Access Control Bypass Vulnerability in Cisco Firewall Products
CVE-2026-20120
5.8MEDIUM
What is CVE-2026-20120?
A vulnerability exists in the access control list (ACL) Object Group Search (OGS) within Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) Software. This issue arises from a logic error when configuring group access control policies, potentially allowing unauthenticated remote attackers to exploit the flaw. By manipulating traffic that should have been blocked, an attacker may gain unauthorized access to protected network devices, leading to serious security risks.
Affected Version(s)
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.23.1
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.22.1.1
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.22.1.3