Description
A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to perform a SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have a valid account on the device with the role of Security Approver, Access Admin, or Network Admin.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain any data from the database, obtain the session credentials of an authenticated Administrator, and take actions with administrative privileges on the affected device.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized database access and privilege escalation via SQL injection
Action: Patch Now
AI Analysis

Impact

A SQL injection flaw exists in the web-based management interface of Cisco Secure Firewall Management Center software. The application fails to properly validate user-supplied input, enabling an attacker who is authenticated with a Security Approver, Access Admin, or Network Admin role to send a crafted HTTP request that injects SQL commands. The successful exploitation grants the attacker unrestricted read access to the database, the ability to extract session credentials of authenticated administrators, and the power to perform any administrative actions on the device. The weakness is identified as CWE-89, which signifies a classic injection vulnerability that bypasses intended access controls.

Affected Systems

The vulnerability affects Cisco Secure Firewall Management Center (FMC) devices. No specific firmware or software version ranges are supplied in the advisory, so all installations of FMC are potential targets until an official fix is published. Users must verify the presence or absence of the issue by consulting Cisco’s patch notes for their installed FMC version.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. The EPSS score is below 1%, suggesting that exploitation is currently considered uncommon, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the attack requires only an account with common administrative roles and uses a standard web interface, a sufficiently motivated attacker can mount the exploit. The risk to an organization therefore remains significant, especially if privileged accounts are not tightly controlled or if the device is exposed to untrusted networks.

Generated by OpenCVE AI on September 18, 2026 at 00:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Cisco Secure FMC release that contains the SQL injection fix
  • If an upgrade is not immediately possible, remove or restrict the Security Approver, Access Admin, and Network Admin roles from any accounts that lack additional hardening
  • Configure the device’s firewall and network segmentation to limit inbound access to the web interface to trusted IP addresses only
  • Implement audit logging and monitor for anomalous SQL queries or unusual administrative activity between the web interface and the database

Generated by OpenCVE AI on September 18, 2026 at 00:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Firewall Management Center
Vendors & Products Cisco
Cisco secure Firewall Management Center

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to perform a SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have a valid account on the device with the role of Security Approver, Access Admin, or Network Admin. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain any data from the database, obtain the session credentials of an authenticated Administrator, and take actions with administrative privileges on the affected device.
Title Cisco Secure Firewall Management Center Software SQL Injection Vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cisco Secure Firewall Management Center
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T13:41:15.734Z

Reserved: 2025-10-08T11:59:15.413Z

Link: CVE-2026-20344

cve-icon Vulnrichment

Updated: 2026-09-18T13:32:32.995Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:11.967

Modified: 2026-09-18T14:17:17.257

Link: CVE-2026-20344

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:31:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')