CVE-2026-76454

Cisco Smart Software Manager On-Prem Unauthenticated API Vulnerability

Severity
Critical 9.1
CVSS 3.1
Remote · no auth what this means
Exploited
Not listed
EPSS
—
Discovered by
Third party
Vendor-published field
Published
Oct 7, 2026
Assigned by cisco

Description

A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS condition on an affected application. This vulnerability is due to improper input validation and a lack of authentication in the management API. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to modify system files or cause a DoS condition.

Weakness: CWE-23

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported products (1)
  • Cisco · Cisco License On-Prem

Vendor advisory

cisco-sa-ssm-access-nttb2dhE

Cisco License (Smart Software Manager) On-Prem Vulnerabilities

Cisco’s rating: Critical (advisory CVSS 9.1) · Published Oct 7, 2026

Bug IDs: CSCwu54774 , CSCwv53803 , CSCwv53807 , CSCwv53814

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?