Cisco Smart Software Manager On-Prem Unauthenticated API Vulnerability
Summary
| CVE | CVE-2026-76454 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-07 17:16:57 UTC |
| Updated | 2026-10-07 17:16:57 UTC |
| Description | A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS condition on an affected application. This vulnerability is due to improper input validation and a lack of authentication in the management API. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to modify system files or cause a DoS condition. |
Risk And Classification
Primary CVSS: v3.1 9.1 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Problem Types: CWE-23 | CWE-23 Relative Path Traversal
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
| 3.1 | CNA | CVSSV3_1 | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Cisco | Cisco License On-Prem | affected 7-202001 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 1.1 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 6.3.0 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202004 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202006 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 1.2 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 1.3 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202012 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202010 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202008 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 9-202201 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202102 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 1.4 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202105 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202108 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202112 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202201 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202206 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202212 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202302 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202303 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202304 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202308 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202401 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 8-202404 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 9-202406 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 9-202407 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 9-202410 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 9-202412 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 9-202501 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 9-202502 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 9-202504 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 9-202507 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 9-202510 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 9-202601 | Not specified |
| CNA | Cisco | Cisco License On-Prem | affected 10-202606 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-ac... | [email protected] | sec.cloudapps.cisco.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Exploits
CNA: The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.
There are currently no legacy QID mappings associated with this CVE.