Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-20328: Cisco License On-Prem lets attackers reset any user password

CVE-2026-20328 · published 4 days ago
Summary

The web management screen of Cisco License On-Prem does not properly verify password‑reset requests. An attacker on the network can send a crafted request and change the password of any account, including administrators, gaining unauthorized access. Apply the vendor’s security update or restrict access to the management interface until the fix is installed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
cisco cisco license on-prem 7-202001
Original advisory text
Cisco Smart Software Manager On-Prem Arbitrary Account Password Reset Vulnerability
A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to gain unauthorized access to an affected application.

This vulnerability is due to improper checks during the password reset process. An attacker could exploit this vulnerability by sending a malicious request to the web-based management interface. A successful exploit could allow the attacker to reset the password of an arbitrary account, including high-privileged administrative user accounts, possibly allowing the attacker to gain unauthorized access to the application as any user.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-862Missing Authorization
Timeline
Published7 Oct 2026
Updated8 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-20328 · MITRE
Track software like this
Free during beta