Skip to content
TrustList
News

Cisco License On-Prem flaw lets anyone reset admin passwords

Editorial

By TrustList Editorial

Versions up to 9-202601 are vulnerable and Cisco offers no workaround. A second critical bug in the same product allows unauthenticated file writes through the API.

About Cisco License On-Prem flaw lets anyone reset admin passwords

Cisco License On-Prem flaw lets anyone reset admin passwords

7 October 2026: Cisco License On-Prem, the product formerly called Smart Software Manager On-Prem, has a critical flaw that lets an unauthenticated attacker reset the password of any account, including administrators. Tracked as CVE-2026-20328 with a CVSS score of 9.1, it sits in the web management interface. Cisco says it has no workaround and that its incident response team knows of no public announcements or malicious use.

The advisory was published on 7 October, with a second critical bug and two medium ones in the same product.

The four vulnerabilities

  • CVE-2026-20328, critical, CVSS 9.1: arbitrary account password reset in the management interface, no authentication needed
  • CVE-2026-76454, critical, CVSS 9.1: an API endpoint with improper input validation and no authentication, which allows arbitrary file writes or a denial of service
  • CVE-2026-76437, medium, CVSS 4.9: command injection that runs OS commands as root, but only for an attacker with administrator credentials
  • CVE-2026-76452, medium, CVSS 4.9: SQL injection that exposes database content to an authenticated administrator

Fixed versions

Release 9-202601 and everything earlier is vulnerable. Release 10-202608 contains the fix, and 10-202609 is listed as not vulnerable. Anyone on the 9 line therefore has to move to the 10 line rather than apply a point update, which makes this a planned upgrade and not a quick patch.

Why the account reset is the one to worry about

An attacker who takes over the administrator account on a reachable server gets control of that licensing server. The two critical bugs need no credentials, so the usual comfort that only administrators can reach the dangerous functions does not apply here.

Teams that run the product should confirm which release each server is on, restrict access to the management interface to the networks that need it until the upgrade is done, and check the administrator accounts for password changes they did not make.

Company profile on TrustList: Cisco

Related on TrustList:

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy