#VU123654 Improper privilege management in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2026-20044

 

#VU123654 Improper privilege management in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2026-20044

Published: March 9, 2026


Vulnerability identifier: #VU123654
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-20044
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper privilege management. A local privileged user can pass specially crafted input to the system CLI of the affected device and execute arbitrary OS commands as root.


Remediation

Install updates from vendor's website.

External links