CVE-2026-20160: Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is due to the unintentional exposure of an internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20160?
CVE-2026-20160 is categorized as a critical vulnerability due to its potential for arbitrary command execution on affected systems.
How do I fix CVE-2026-20160?
To mitigate CVE-2026-20160, update the Cisco Smart Software Manager On-Prem to the latest patched version as recommended by Cisco.
What types of systems are affected by CVE-2026-20160?
CVE-2026-20160 affects Cisco Smart Software Manager On-Prem installations.
Can CVE-2026-20160 be exploited remotely?
Yes, CVE-2026-20160 can be exploited by unauthenticated, remote attackers.
What impact does CVE-2026-20160 have on system security?
CVE-2026-20160 allows attackers to execute arbitrary commands, potentially leading to full system compromise.