Skip to content

CVE-2026-20328 CVE-2026-76454 CVE-2026-76437 CVE-2026-76452

Cisco License On-Prem vulnerabilities allow unauthenticated password reset and arbitrary file writes (CVE-2026-20328, CVE-2026-76454)

Critical 9.1 Vendor: Cisco Published

Cisco License On-Prem has two critical flaws: unauthenticated password reset and arbitrary file writes or denial of service. Two medium flaws need admin credentials. Cisco has made fixes available; no workarounds. Apply the update and restrict access.

What happened

Cisco's advisory covers four vulnerabilities in Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem. Two are rated critical. CVE-2026-20328 stems from improper checks during the password reset process. An unauthenticated, remote attacker can send a malicious request to the web-based management interface and reset the password of an arbitrary account, including high-privileged administrative accounts, then access the application as that user. It has a CVSS score of 9.1.

CVE-2026-76454 affects the Smart Licensing Utility API. Because of improper input validation and missing authentication in the management API, an unauthenticated, remote attacker can send a crafted request to write arbitrary files to the system or cause a denial-of-service condition. This flaw is also rated 9.1.

CVE-2026-76437 and CVE-2026-76452 require valid administrative credentials. The first is a command injection flaw that could allow command execution as root, though Cisco notes the additional privilege gained is limited to turning the system off. The second is a SQL injection flaw that could allow reading additional database contents not normally accessible to administrative users. Both have a CVSS score of 4.9. Cisco PSIRT states it is not aware of public announcements or malicious use related to these vulnerabilities.

Who is affected

The affected product is Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem. The advisory lists the following affected versions: 7-202001, 1.1, 6.3.0, 8-202004, 8-202006, 1.2, 1.3, and 8-202012. This product typically provides on-premises license management for Cisco software, and the vulnerabilities involve its web-based management interface and Smart Licensing Utility API. Organisations that expose either service to untrusted networks are the most immediately concerned; even internal-only deployments should patch because the pre-authentication flaws permit network-based compromise without user interaction.

What to do now

  1. Confirm which Cisco License On-Prem instances you run and compare their versions against the affected list.
  2. Apply the fixed release Cisco has made available. The advisory does not include a specific fixed version number, so use Cisco's advisory link to identify the appropriate update.
  3. Restrict access to the web-based management interface and the Smart Licensing Utility API, especially from the internet, until patching is complete.
  4. Review local accounts and administrative credentials for unexpected changes, since CVE-2026-20328 permits arbitrary account password resets.

How to detect it

Start by checking whether the web-based management interface or Smart Licensing Utility API is reachable from untrusted networks. The critical flaws are network-based and do not require credentials, so reachability is the primary immediate exposure. Cisco has not published specific indicators of compromise, but review administrative accounts for unexpected password resets and watch the host for unexpected file modifications that may indicate API misuse.

Beyond the patch

Two of these flaws are reachable over the network without credentials, which makes an exposed service or open port an exposure problem before it is a patching problem. Virtual CISO Services (vCISO) can help identify that exposure, and Supply Chain Defense & Third-Party Risk helps track which vendors' software you run and how quickly they fix it, because Cisco's patch cycle sets the window you need to manage.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-20328, CVE-2026-76454, CVE-2026-76437, CVE-2026-76452
Cisco License On-Prem
7-202001
1.1
6.3.0
8-202004
8-202006
1.2
1.3
8-202012
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.