CVE-2026-20342
Cisco Secure Firewall Management Center Software Low Privileged Arbitrary File Download Vulnerability
Description
A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability exists because user input is not being sanitized. An attacker could exploit this vulnerability by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from the affected system. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Security Analyst (read-only).
In plain language
AI Act nowCisco Secure Firewall Management Center has a flaw that lets a low-level account download files it should not see, so businesses using it should act now.
Authenticated arbitrary file read through the Cisco Secure Firewall Management Center file-download API due to improper authorization/input handling (CWE-639).
What to do now
- Check whether your organization runs Cisco Secure Firewall Management Center and identify all accounts with Security Analyst or higher access.
- There is no published fixed version yet; ask Cisco or your support provider for the official remediation and upgrade guidance for CVE-2026-20342.
- Until a fix is available, restrict Security Analyst access to trusted staff, remove unused accounts, and review recent file-download activity.
- Rotate passwords and access tokens if you find unexpected file downloads or suspicious account use.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20342 and every CVE in our database. Create a free account — no credit card required.
Create Free Account