SQL Injection Vulnerability in Cisco Secure FMC Software
CVE-2026-20344
8.8HIGH
What is CVE-2026-20344?
An SQL injection vulnerability exists in the web-based management interface of Cisco Secure FMC Software due to inadequate validation of user input. An authenticated attacker with roles such as Security Approver, Access Admin, or Network Admin could exploit this weakness by submitting specially crafted HTTP requests. This exploitation can result in unauthorized access to the database, potentially allowing the attacker to retrieve sensitive information, including session credentials of an authenticated Administrator, leading to actions with elevated privileges on the affected device.
Affected Version(s)
Cisco Secure Firewall Management Center (FMC) 7.0.0
Cisco Secure Firewall Management Center (FMC) 7.0.0.1
Cisco Secure Firewall Management Center (FMC) 7.0.1