Cisco FXOS CLI Auth Local RCE (root)
CVE-2026-20016 Published on March 4, 2026
A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. To exploit this vulnerability, the attacker must have valid administrative credentials on an affected device. This vulnerability is due to insufficient input validation of user-supplied command arguments. An attacker could exploit this vulnerability by submitting crafted input for specific CLI commands. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.
Vulnerability Analysis
CVE-2026-20016 is exploitable with local system access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is an Argument Injection Vulnerability?
The software constructs a string for a command to executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
CVE-2026-20016 has been classified to as an Argument Injection vulnerability or weakness.
Affected Versions
Cisco Secure Firewall Threat Defense (FTD) Software:- Version 7.0.0 is affected.
- Version 7.0.0.1 is affected.
- Version 7.0.1 is affected.
- Version 7.0.1.1 is affected.
- Version 7.0.2 is affected.
- Version 7.0.2.1 is affected.
- Version 7.0.3 is affected.
- Version 7.0.4 is affected.
- Version 7.0.5 is affected.
- Version 7.0.6 is affected.
- Version 7.0.6.1 is affected.
- Version 7.0.6.2 is affected.
- Version 7.0.6.3 is affected.
- Version 7.0.7 is affected.
- Version 7.0.8 is affected.
- Version 7.0.8.1 is affected.
- Version 7.1.0 is affected.
- Version 7.1.0.1 is affected.
- Version 7.1.0.3 is affected.
- Version 7.2.0 is affected.
- Version 7.2.0.1 is affected.
- Version 7.2.1 is affected.
- Version 7.2.2 is affected.
- Version 7.2.3 is affected.
- Version 7.2.4 is affected.
- Version 7.2.4.1 is affected.
- Version 7.2.5 is affected.
- Version 7.2.5.1 is affected.
- Version 7.2.6 is affected.
- Version 7.2.7 is affected.
- Version 7.2.5.2 is affected.
- Version 7.2.8 is affected.
- Version 7.2.8.1 is affected.
- Version 7.2.9 is affected.
- Version 7.2.10 is affected.
- Version 7.2.10.2 is affected.
- Version 7.3.0 is affected.
- Version 7.3.1 is affected.
- Version 7.3.1.1 is affected.
- Version 7.3.1.2 is affected.
- Version 7.4.1 is affected.
- Version 7.4.1.1 is affected.
- Version 7.4.2 is affected.
- Version 7.4.2.1 is affected.
- Version 7.4.2.2 is affected.
- Version 7.4.2.3 is affected.
- Version 7.4.2.4 is affected.
- Version 7.4.3 is affected.
- Version 7.6.0 is affected.
- Version 7.6.1 is affected.
- Version 7.6.2 is affected.
- Version 7.6.2.1 is affected.
- Version 7.7.0 is affected.
- Version 7.7.10 is affected.
- Version 7.7.10.1 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.