Executive brief
Cisco Secure Firewall Management Center (FMC) is a centralized management platform for Cisco firewall appliances. A vulnerability in its file download API allows authenticated users with the Security Analyst role to download arbitrary files from the system, potentially exposing sensitive configuration data, logs, and other confidential information stored on the management server.
Technical details
CVE-2026-20342 is an arbitrary file download vulnerability in Cisco Secure FMC Software caused by insufficient input sanitization in a specific file download API endpoint. The vulnerability requires valid credentials for a user account with at least the Security Analyst (read-only) role to exploit. An attacker with such credentials can send a crafted HTTPS request to bypass path validation and download arbitrary files from the affected system. A successful exploit allows an authenticated attacker to access sensitive files they should not have permission to retrieve. Cisco has released software updates to address this vulnerability.
Affected products
- Cisco Secure Firewall Management Center Software
Timeline
- 2026-09-16: disclosed