Command Execution Vulnerability in Cisco License On-Prem Web Interface
CVE-2026-76437

4.9MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
7 October 2026

Badges

👾 Exploit Exists

What is CVE-2026-76437?

A serious vulnerability exists in the web-based user interface of Cisco License On-Prem, formerly known as Cisco Smart Software Manager On-Prem. This flaw arises from inadequate validation of user-submitted configurations. If an authenticated user with administrative access modifies the configurations, they could inadvertently allow an attacker to execute arbitrary commands on the system's underlying operating system with root privileges. Consequently, this vulnerability poses significant risks, including the potential for unauthorized administrative actions that could severely impact system operations.

Affected Version(s)

Cisco License On-Prem 7-202001

Cisco License On-Prem 1.1

Cisco License On-Prem 6.3.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.