Executive brief
Cisco Secure Firewall Management Center (FMC) is the centralized management platform for enterprise firewall networks. A flaw in its remote diagnostics debugger allows authenticated users to escalate their privileges to root, potentially giving attackers complete control over the firewall management infrastructure and all protected networks downstream. An attacker with valid credentials can exploit this via the web interface or REST API to gain root access.
Technical details
CVE-2026-76412 is a privilege escalation vulnerability caused by improper privilege-level validation in the remote diagnostics debugger of Cisco Secure FMC. The vulnerability exists in the debugger's privilege checking logic when users invoke remote diagnostics functions. An authenticated remote attacker can exploit this by sending requests through the web-based management interface or REST API to enable the remote diagnostics debugger and grant themselves elevated privileges, ultimately achieving root-level access. The attack requires valid user credentials on the device and involves a multistage process, resulting in a high attack complexity rating. Cisco has released software updates to address this vulnerability; no workarounds are available.
Affected products
- Cisco Secure Firewall Management Center
Timeline
- 2026-09-16: disclosed