CVE-2026-20160
Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
Severity
Critical 9.8
CVSS 3.1
Exploited
Not listed
EPSS
0.009
56.7th percentile
Discovered by
Vendor
Published by the vendor
Published
Apr 1, 2026
Assigned by cisco
Description
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is due to the unintentional exposure of an internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.
Weakness: CWE-668
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Smart Software Manager On-Prem | Network & Security Management | cna-assigner |
Vendor-reported affected versions (1)
- Cisco · Cisco Smart Software Manager On-Prem