File Download API Vulnerability in Cisco Secure FMC Software
CVE-2026-20342
7.7HIGH
What is CVE-2026-20342?
A security flaw in the file download API of Cisco Secure FMC Software permits authenticated remote attackers to exploit unsanitized user input. By issuing a specially crafted HTTPS request, an attacker with valid user credentials, particularly those assigned the Security Analyst role, could potentially download arbitrary files from the target system. This vulnerability highlights the necessity for improved input validation measures to prevent unauthorized file access.
Affected Version(s)
Cisco Secure Firewall Management Center (FMC) 7.0.0
Cisco Secure Firewall Management Center (FMC) 7.0.0.1
Cisco Secure Firewall Management Center (FMC) 7.0.1