{"id":"CVE-2026-20160","title":"A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host.\r\n\r\nThis vulnerability…","summary":"A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host.\r\n\r\nThis vulnerability…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-668"],"vendor":"cisco","product":"smart_software_manager_on-prem","affected":["smart_software_manager_on-prem >= 9-202502, < 9-202601"],"patched":["smart_software_manager_on-prem 9-202601"],"published":"2026-04-01","updated":"2026-07-01","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20160","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr","label":"psirt@cisco.com"}],"tags":["nvd"],"epss":0.00914,"epssPercentile":0.58047,"ingestedAt":"2026-07-01T15:50:58.752Z","slug":"CVE-2026-20160","body":"## Overview\n\nA vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host.\r\n\r\nThis vulnerability is due to the unintentional exposure of an&nbsp;internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.\n\n## Affected\n\n- `smart_software_manager_on-prem >= 9-202502, < 9-202601`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `smart_software_manager_on-prem 9-202601`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}