Junglewise Threat Intelligence

CVE-2026-20102: Cisco Secure Firewall ASA SAML reflected XSS

CVE-2026-20102 · Severity: medium · CVSS 6.1 · Published 2026-03-04

Technologies: Cisco Secure Firewall ASA Software, Cisco Secure Firewall Threat Defense Software. Vendors: Cisco.

Executive brief

Cisco Secure Firewall ASA and Threat Defense (FTD) devices that support SAML 2.0 single sign-on (SSO) for remote access VPN are vulnerable to reflected cross-site scripting (XSS) attacks. An attacker can craft a malicious link that, when clicked by a user, injects malicious code into the browser and steals sensitive information or hijack the user's session. This affects firewall administrators and remote workers who authenticate through the SAML SSO feature.

Technical details

This vulnerability is a reflected XSS (CWE-79) in the SAML 2.0 SSO feature, caused by insufficient input validation of HTTP parameters. The attack requires an unauthenticated attacker to persuade a user (typically an administrator or remote VPN user) to click a malicious link pointing to the affected device. The vulnerability has a network attack vector and requires user interaction (social engineering) to succeed. A successful exploit allows the attacker to conduct a reflected XSS attack through the SAML SSO endpoint, potentially accessing sensitive browser-based information or session tokens. Cisco has released software updates to address this issue; no workarounds are available.

Affected products

  • Cisco Secure Firewall ASA Software Multiple releases (see Cisco advisory for complete version matrix)
  • Cisco Secure Firewall Threat Defense Software Multiple releases (see Cisco advisory for complete version matrix)

Timeline

  • 2026-03-04: disclosed: Cisco published security advisory

References

Related threats