CVE-2026-20102: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SAML Reflected Cross-Site Scripting Vulnerability
A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the SAML feature and access sensitive, browser-based information. This vulnerability is due to insufficient input validation of multiple HTTP parameters. An attacker could exploit this vulnerability by persuading a user to access a malicious link. A successful exploit could allow the attacker to conduct a reflected XSS attack through an affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20102?
CVE-2026-20102 is classified as a high-severity vulnerability due to the risk of reflected cross-site scripting attacks.
How do I fix CVE-2026-20102?
To remediate CVE-2026-20102, users should update to the latest patched version of Cisco Secure Firewall ASA Software or Secure Firewall Threat Defense Software.
What systems are affected by CVE-2026-20102?
CVE-2026-20102 affects Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense Software that utilize SAML 2.0 for single sign-on.
What type of vulnerability is CVE-2026-20102?
CVE-2026-20102 is a reflected cross-site scripting vulnerability affecting the SAML SSO feature.
Can CVE-2026-20102 be exploited remotely?
Yes, CVE-2026-20102 can potentially be exploited remotely, allowing attackers to execute malicious scripts in the context of a user's session.