Executive brief
Cisco Secure Firewall Management Center (FMC) is a centralized management platform for Cisco firewall deployments. A SQL injection vulnerability in its REST API allows authenticated administrators to read database records and files from the underlying system without proper authorization checks. An attacker with valid credentials can craft malicious API requests to bypass database access controls.
Technical details
CVE-2026-20003 is a SQL injection vulnerability (CWE-89) in the REST API of Cisco Secure FMC Software, stemming from inadequate input validation on user-supplied parameters. The vulnerability requires network access and valid user credentials with at least one of these roles: Administrator, Security approver, Intrusion admin, Access admin, or Network admin. An authenticated remote attacker can send crafted API requests to extract database contents and read certain operating system files. The attack vector is network-based with low complexity, and successful exploitation yields confidentiality impact (read-only database access) but no integrity or availability impact. Cisco has released software updates to address this vulnerability; no workarounds are available.
Affected products
- Cisco Secure Firewall Management Center
Timeline
- 2026-03-04: disclosed