CVE-2026-20344
8.8Cisco · Secure Firewall Management Center (FMC)
Cisco Secure FMC contains a SQL injection vulnerability in its web interface, allowing an authenticated attacker with administrative-level roles to execute arbitrary database queries.
Executive summary
An authenticated SQL injection vulnerability in Cisco Secure Firewall Management Center poses a high risk of full administrative compromise and unauthorized data access.
Vulnerability
This is a SQL injection flaw (CWE-89) within the web-based management interface, triggered by insufficient input validation. The attack requires an authenticated user with elevated privileges, such as a Security Approver, Access Admin, or Network Admin, to send a crafted HTTP request to the target device.
Business impact
A successful exploitation of this vulnerability allows an attacker to extract sensitive information from the underlying database or hijack the session credentials of a primary Administrator. Given the CVSS score of 8.8, this flaw represents a significant risk to the integrity and confidentiality of the entire security management ecosystem, potentially granting the attacker full control over the firewall infrastructure.
Remediation
Immediate Action: Review the official Cisco security advisory for available hotfixes or software updates and apply them to all affected management appliances immediately.
Proactive Monitoring: Monitor management interface logs for anomalous HTTP requests containing SQL syntax or unusual patterns indicative of injection attempts.
Compensating Controls: Restrict access to the management interface to authorized networks and enforce strict role-based access control (RBAC) to minimize the number of users holding the vulnerable administrative roles.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations using the affected versions of Cisco Secure FMC should prioritize this update as part of their next maintenance cycle. Because this vulnerability allows for administrative privilege escalation, it is imperative to verify that all administrative accounts are secured and that any suspicious activity within the management console is investigated with high urgency.
More Cisco CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section