Unauth Rmt File Write & DoS via Cisco Smart Licensing Utility API
CVE-2026-76454 Published on October 7, 2026
Cisco Smart Software Manager On-Prem Unauthenticated API Vulnerability
A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS condition on an affected application.
This vulnerability is due to improper input validation and a lack of authentication in the management API. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to modify system files or cause a DoS condition.
Vulnerability Analysis
CVE-2026-76454 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity and availability.
Weakness Type
Relative Path Traversal
The software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory. This allows attackers to traverse the file system to access files or directories that are outside of the restricted directory.
Affected Versions
Cisco License On-Prem:- Version 7-202001 is affected.
- Version 1.1 is affected.
- Version 6.3.0 is affected.
- Version 8-202004 is affected.
- Version 8-202006 is affected.
- Version 1.2 is affected.
- Version 1.3 is affected.
- Version 8-202012 is affected.
- Version 8-202010 is affected.
- Version 8-202008 is affected.
- Version 9-202201 is affected.
- Version 8-202102 is affected.
- Version 1.4 is affected.
- Version 8-202105 is affected.
- Version 8-202108 is affected.
- Version 8-202112 is affected.
- Version 8-202201 is affected.
- Version 8-202206 is affected.
- Version 8-202212 is affected.
- Version 8-202302 is affected.
- Version 8-202303 is affected.
- Version 8-202304 is affected.
- Version 8-202308 is affected.
- Version 8-202401 is affected.
- Version 8-202404 is affected.
- Version 9-202406 is affected.
- Version 9-202407 is affected.
- Version 9-202410 is affected.
- Version 9-202412 is affected.
- Version 9-202501 is affected.
- Version 9-202502 is affected.
- Version 9-202504 is affected.
- Version 9-202507 is affected.
- Version 9-202510 is affected.
- Version 9-202601 is affected.
- Version 10-202606 is affected.