SQL Injection Vulnerability in Cisco Secure FMC Software
CVE-2026-20344

8.8HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-20344?

An SQL injection vulnerability exists in the web-based management interface of Cisco Secure FMC Software due to inadequate validation of user input. An authenticated attacker with roles such as Security Approver, Access Admin, or Network Admin could exploit this weakness by submitting specially crafted HTTP requests. This exploitation can result in unauthorized access to the database, potentially allowing the attacker to retrieve sensitive information, including session credentials of an authenticated Administrator, leading to actions with elevated privileges on the affected device.

Affected Version(s)

Cisco Secure Firewall Management Center (FMC) 7.0.0

Cisco Secure Firewall Management Center (FMC) 7.0.0.1

Cisco Secure Firewall Management Center (FMC) 7.0.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.