File Download API Vulnerability in Cisco Secure FMC Software
CVE-2026-20342

7.7HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-20342?

A security flaw in the file download API of Cisco Secure FMC Software permits authenticated remote attackers to exploit unsanitized user input. By issuing a specially crafted HTTPS request, an attacker with valid user credentials, particularly those assigned the Security Analyst role, could potentially download arbitrary files from the target system. This vulnerability highlights the necessity for improved input validation measures to prevent unauthorized file access.

Affected Version(s)

Cisco Secure Firewall Management Center (FMC) 7.0.0

Cisco Secure Firewall Management Center (FMC) 7.0.0.1

Cisco Secure Firewall Management Center (FMC) 7.0.1

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.