CVE-2026-20328 is a critical (CVSS 9.1) flaw in the web management interface of Cisco License On-Prem. A remote attacker with no credentials can use it to reset the password of any account, including administrator accounts.
What Is It
CVE-2026-20328 affects the web-based management interface of Cisco License On-Prem, which was formerly called Cisco Smart Software Manager On-Prem (SSM On-Prem). The cause is improper checks during the password reset process, classified as CWE-862 (Missing Authorization). An attacker can exploit it by sending a malicious request to the management interface. If the attack works, the attacker can reset the password of any account and may then log in to the application as any user.
Cisco PSIRT published the issue on 2026-10-07. NVD lists the record as "Received," so NVD has not finished analyzing it.
Why It Matters
Cisco scores the flaw 9.1 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N:
- No authentication or user interaction is needed. Attackers can exploit it over the network with low complexity.
- Admin takeover: Any password can be reset, including passwords for high-privileged administrative accounts.
- High impact on confidentiality and integrity. Availability is not affected.
CISA's SSVC assessment, dated 2026-10-07, rates technical impact as total, exploitation as none, and automatable as no. The CVE is not in the CISA Known Exploited Vulnerabilities (KEV) catalog, so there is no confirmed active exploitation at this time.
What's Vulnerable
The affected product is Cisco License On-Prem, formerly SSM On-Prem. The CVE record lists a wide range of releases as affected:
- Version 6.3.0
- Versions 1.1 through 1.4
- 7-202001
- The 8-series, from 8-202004 through 8-202404
- The 9-series, from 9-202201 and 9-202406 through 9-202601
- 10-202606
The record does not include CPE data.
Patch Status
The supplied NVD record does not name any fixed versions or workarounds. Check the Cisco Security Advisory (cisco-sa-ssm-access-nttb2dhE) for fixed releases and upgrade guidance. CISA has set no required action or due date, because the CVE is not in KEV.
If you run License On-Prem, review the advisory now. Because the flaw allows unauthenticated admin takeover through the web interface, limit network exposure of the management interface until you can apply a fix.