CVE-2026-20344
Cisco Secure Firewall Management Center Software SQL Injection Vulnerability
Description
A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to perform a SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have a valid account on the device with the role of Security Approver, Access Admin, or Network Admin. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain any data from the database, obtain the session credentials of an authenticated Administrator, and take actions with administrative privileges on the affected device.
In plain language
AI Act nowA serious flaw in Cisco Secure Firewall Management Center lets a privileged user take over the management system; small businesses using it should act now.
Authenticated SQL injection in the Cisco Secure Firewall Management Center web management interface allows Security Approver, Access Admin, or Network Admin users to extract database data, hijack an Administrator session, and perform administrative actions.
What to do now
- Check whether you run Cisco Secure Firewall Management Center and identify everyone assigned Security Approver, Access Admin, or Network Admin roles.
- No fixed version has been published; ask Cisco or your support provider for the vendor-approved remediation and release plan for CVE-2026-20344.
- Immediately remove unnecessary privileged accounts, require multi-factor authentication where available, and restrict management-interface access to trusted administrator networks.
- Review recent administrator logins, role changes, configuration changes, and new accounts for unexpected activity.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20344 and every CVE in our database. Create a free account — no credit card required.
Create Free Account