CVE-2026-76454: Cisco Smart Software Manager On-Prem Unauthenticated API Vulnerability
A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS condition on an affected application. This vulnerability is due to improper input validation and a lack of authentication in the management API. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to modify system files or cause a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
No authentication, privileges, or user interaction are required. A remote attacker can exploit the issue by sending a crafted request to the affected management API.
What could a successful attack do?
An attacker could write arbitrary files, including modifying system files, or cause a denial-of-service condition on the affected application.
Which deployments are exposed?
The affected product identified in the available data is Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem. Exposure depends on the vulnerable Cisco Smart Licensing Utility management API being reachable by a remote attacker.