---
id: CVE-2026-20328
title: >-
  A vulnerability in the web-based management interface of Cisco License
  On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could
  allow an unauthenticated, remote attacker to gain unauthorized access to an
  affected appli…
summary: >-
  A vulnerability in the web-based management interface of Cisco License
  On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could
  allow an unauthenticated, remote attacker to gain unauthorized access to an
  affected appli…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-862
vendor: Cisco
product: Cisco License On-Prem
affected:
  - license_on-prem 7-202001
  - license_on-prem 1.1
  - license_on-prem 6.3.0
  - license_on-prem 8-202004
  - license_on-prem 8-202006
  - license_on-prem 1.2
  - license_on-prem 1.3
  - license_on-prem 8-202012
  - license_on-prem 8-202010
  - license_on-prem 8-202008
  - license_on-prem 9-202201
  - license_on-prem 8-202102
  - license_on-prem 1.4
  - license_on-prem 8-202105
  - license_on-prem 8-202108
  - license_on-prem 8-202112
  - license_on-prem 8-202201
  - license_on-prem 8-202206
  - license_on-prem 8-202212
  - license_on-prem 8-202302
  - license_on-prem 8-202303
  - license_on-prem 8-202304
  - license_on-prem 8-202308
  - license_on-prem 8-202401
  - license_on-prem 8-202404
  - license_on-prem 9-202406
  - license_on-prem 9-202407
  - license_on-prem 9-202410
  - license_on-prem 9-202412
  - license_on-prem 9-202501
  - license_on-prem 9-202502
  - license_on-prem 9-202504
  - license_on-prem 9-202507
  - license_on-prem 9-202510
  - license_on-prem 9-202601
  - license_on-prem 10-202606
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T17:16:55.157'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20328'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-access-nttb2dhE
    label: psirt@cisco.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-07T16:55:05.469099Z'
ingestedAt: '2026-10-07T16:38:22.256Z'
---

## Overview

A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to gain unauthorized access to an affected application.

This vulnerability is due to improper checks during the password reset process. An attacker could exploit this vulnerability by sending a malicious request to the web-based management interface. A successful exploit could allow the attacker to reset the password of an arbitrary account, including high-privileged administrative user accounts, possibly allowing the attacker to gain unauthorized access to the application as any user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
