Cyber & AI intelligence
Wasteland.
Briefs indexed3048
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-20328 2026-10-07

Cisco License On-Prem Password Reset Flaw Lets Unauthenticated Attackers Take Over Admin Accounts (CVE-2026-20328)

"CVE-2026-20328 is a critical (CVSS 9.1) flaw in the web management interface of Cisco License On-Prem. A remote attacker with no credentials can use it to reset the password of any account, including administrator…"

CVE-2026-20328 is a critical (CVSS 9.1) flaw in the web management interface of Cisco License On-Prem. A remote attacker with no credentials can use it to reset the password of any account, including administrator accounts.

What Is It

CVE-2026-20328 affects the web-based management interface of Cisco License On-Prem, which was formerly called Cisco Smart Software Manager On-Prem (SSM On-Prem). The cause is improper checks during the password reset process, classified as CWE-862 (Missing Authorization). An attacker can exploit it by sending a malicious request to the management interface. If the attack works, the attacker can reset the password of any account and may then log in to the application as any user.

Cisco PSIRT published the issue on 2026-10-07. NVD lists the record as "Received," so NVD has not finished analyzing it.

Why It Matters

Cisco scores the flaw 9.1 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N:

CISA's SSVC assessment, dated 2026-10-07, rates technical impact as total, exploitation as none, and automatable as no. The CVE is not in the CISA Known Exploited Vulnerabilities (KEV) catalog, so there is no confirmed active exploitation at this time.

What's Vulnerable

The affected product is Cisco License On-Prem, formerly SSM On-Prem. The CVE record lists a wide range of releases as affected:

The record does not include CPE data.

Patch Status

The supplied NVD record does not name any fixed versions or workarounds. Check the Cisco Security Advisory (cisco-sa-ssm-access-nttb2dhE) for fixed releases and upgrade guidance. CISA has set no required action or due date, because the CVE is not in KEV.

If you run License On-Prem, review the advisory now. Because the flaw allows unauthenticated admin takeover through the web interface, limit network exposure of the management interface until you can apply a fix.

Sources