Cisco License On-Prem flaw lets anyone reset admin passwords
EditorialBy TrustList Editorial
Versions up to 9-202601 are vulnerable and Cisco offers no workaround. A second critical bug in the same product allows unauthenticated file writes through the API.
- Cybersecurity
- Vulnerability Management
- License Management
About Cisco License On-Prem flaw lets anyone reset admin passwords
Cisco License On-Prem flaw lets anyone reset admin passwords
7 October 2026: Cisco License On-Prem, the product formerly called Smart Software Manager On-Prem, has a critical flaw that lets an unauthenticated attacker reset the password of any account, including administrators. Tracked as CVE-2026-20328 with a CVSS score of 9.1, it sits in the web management interface. Cisco says it has no workaround and that its incident response team knows of no public announcements or malicious use.
The advisory was published on 7 October, with a second critical bug and two medium ones in the same product.
The four vulnerabilities
- CVE-2026-20328, critical, CVSS 9.1: arbitrary account password reset in the management interface, no authentication needed
- CVE-2026-76454, critical, CVSS 9.1: an API endpoint with improper input validation and no authentication, which allows arbitrary file writes or a denial of service
- CVE-2026-76437, medium, CVSS 4.9: command injection that runs OS commands as root, but only for an attacker with administrator credentials
- CVE-2026-76452, medium, CVSS 4.9: SQL injection that exposes database content to an authenticated administrator
Fixed versions
Release 9-202601 and everything earlier is vulnerable. Release 10-202608 contains the fix, and 10-202609 is listed as not vulnerable. Anyone on the 9 line therefore has to move to the 10 line rather than apply a point update, which makes this a planned upgrade and not a quick patch.
Why the account reset is the one to worry about
An attacker who takes over the administrator account on a reachable server gets control of that licensing server. The two critical bugs need no credentials, so the usual comfort that only administrators can reach the dangerous functions does not apply here.
Teams that run the product should confirm which release each server is on, restrict access to the management interface to the networks that need it until the upgrade is done, and check the administrator accounts for password changes they did not make.
Company profile on TrustList: Cisco
Related on TrustList:
Sources
Categories & features
- Cybersecurity
- Vulnerability Management
- License Management
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.