Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
4.9
Cisco Secure FMC Software: SQL Injection via Authenticated Request
CVE-2026-20003
Summary
If an attacker has valid credentials, they can send malicious requests to access sensitive data and files on a Cisco Secure FMC system. This is a concern because it means an attacker with proper access can potentially gain more information than they should. To protect your system, ensure that user credentials are properly managed and validated.
Original title
A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
This vulnerability is due to in...
Original description
A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted requests to an affected device. A successful exploit could allow the attacker to obtain read access to the database and read certain files on the underlying operating system. To exploit this vulnerability, the attacker would need valid user credentials with any of the following roles:
Administrator
Security approver
Intrusion admin
Access admin
Network admin
This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted requests to an affected device. A successful exploit could allow the attacker to obtain read access to the database and read certain files on the underlying operating system. To exploit this vulnerability, the attacker would need valid user credentials with any of the following roles:
Administrator
Security approver
Intrusion admin
Access admin
Network admin
nvd CVSS3.1
4.9
Vulnerability type
CWE-89
SQL Injection
Published: 4 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026