
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20342 is an arbitrary file download vulnerability in Cisco Secure Firewall Management Center (FMC) Software, classified as an Authorization Bypass Through User-Controlled Key (CWE-639). It allows an authenticated remote attacker with at least Security Analyst (read-only) role credentials to download arbitrary files from the affected system by sending a crafted HTTPS request to a specific file download API. The vulnerability was publicly disclosed on September 16, 2026, as part of a broader Cisco security advisory (cisco-sa-fmc-mulivulns-4PsnFwvx) covering multiple FMC vulnerabilities. Affected versions span a wide range including 7.0.x through 7.7.x and 10.0.x releases. It carries a CVSS v3.1 base score of 7.7 (High) (Cisco Advisory, GitHub Advisory).
The root cause is insufficient sanitization of user-supplied input in a specific file download API endpoint of Cisco Secure FMC Software, classified as CWE-639 (Authorization Bypass Through User-Controlled Key). An attacker exploits this by crafting an HTTPS request that manipulates the key or path parameter used to identify the file to be downloaded, bypassing the intended access restrictions and allowing retrieval of files outside the scope of the user's role. The attack requires network access to the FMC management interface and valid low-privilege credentials (Security Analyst read-only role or higher), but no user interaction or elevated privileges beyond that. Cisco Bug ID CSCwu42586 tracks this specific issue (Cisco Advisory).
Successful exploitation allows an authenticated attacker to download arbitrary files from the Cisco Secure FMC system, including sensitive configuration files, credentials, cryptographic material, and system files that are not normally accessible to a Security Analyst role. The confidentiality impact is rated High with a changed scope, meaning files beyond the attacker's authorized access boundary can be retrieved. There is no direct integrity or availability impact, but exfiltrated data could facilitate further attacks such as credential theft, lateral movement to managed Firepower Threat Defense (FTD) devices, or privilege escalation (Cisco Advisory, GitHub Advisory).
As of the disclosure date (September 16, 2026), Cisco's Product Security Incident Response Team (PSIRT) is not aware of any public proof-of-concept exploit code or malicious use of this vulnerability in the wild. The EPSS score is 0.0, reflecting low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid credentials for at least a Security Analyst (read-only) account, which limits the attack surface compared to unauthenticated vulnerabilities. The vulnerability was reported by Christophe Schleypen from the NATO Cyber Security Centre (NCSC) (Cisco Advisory).
/etc/passwd, SSH key files, database configuration files).Cisco has released fixed software updates to address this vulnerability; there are no workarounds available. Customers should use the Cisco Software Checker to identify the appropriate fixed release for their deployment. As interim measures, organizations should restrict network access to the FMC management interface to trusted administrative networks only, audit and review accounts with Security Analyst roles, and monitor access logs for anomalous file download API activity. Customers without a Cisco service contract should contact the Cisco Technical Assistance Center (TAC) to obtain the fixed software (Cisco Advisory).
The vulnerability was reported to Cisco by Christophe Schleypen from the NATO Cyber Security Centre (NCSC), indicating it was discovered through responsible disclosure by a government cybersecurity organization. Cisco's PSIRT confirmed no public announcements or malicious exploitation at the time of disclosure. The advisory was part of a broader September 16, 2026 Cisco security publication covering multiple critical and high-severity FMC vulnerabilities, which received coverage from security aggregators including AusCERT and VulDB (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."