{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-76454","assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","state":"PUBLISHED","assignerShortName":"cisco","dateReserved":"2026-08-19T12:02:03.636Z","datePublished":"2026-10-07T16:12:31.265Z","dateUpdated":"2026-10-07T16:54:07.562Z"},"containers":{"cna":{"title":"Cisco Smart Software Manager On-Prem Unauthenticated API Vulnerability","metrics":[{"format":"cvssV3_1","cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"}}],"descriptions":[{"lang":"en","value":"A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS condition on an affected application.\r\n\r\nThis vulnerability is due to improper input validation and a lack of authentication in the management API. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to modify system files or cause a DoS condition."}],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-access-nttb2dhE","name":"cisco-sa-ssm-access-nttb2dhE"}],"exploits":[{"lang":"en","value":"The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."}],"source":{"advisory":"cisco-sa-ssm-access-nttb2dhE","discovery":"EXTERNAL","defects":["CSCwu54774"]},"problemTypes":[{"descriptions":[{"lang":"en","description":"Relative Path Traversal","type":"cwe","cweId":"CWE-23"}]}],"affected":[{"vendor":"Cisco","product":"Cisco License On-Prem","versions":[{"version":"7-202001","status":"affected"},{"version":"1.1","status":"affected"},{"version":"6.3.0","status":"affected"},{"version":"8-202004","status":"affected"},{"version":"8-202006","status":"affected"},{"version":"1.2","status":"affected"},{"version":"1.3","status":"affected"},{"version":"8-202012","status":"affected"},{"version":"8-202010","status":"affected"},{"version":"8-202008","status":"affected"},{"version":"9-202201","status":"affected"},{"version":"8-202102","status":"affected"},{"version":"1.4","status":"affected"},{"version":"8-202105","status":"affected"},{"version":"8-202108","status":"affected"},{"version":"8-202112","status":"affected"},{"version":"8-202201","status":"affected"},{"version":"8-202206","status":"affected"},{"version":"8-202212","status":"affected"},{"version":"8-202302","status":"affected"},{"version":"8-202303","status":"affected"},{"version":"8-202304","status":"affected"},{"version":"8-202308","status":"affected"},{"version":"8-202401","status":"affected"},{"version":"8-202404","status":"affected"},{"version":"9-202406","status":"affected"},{"version":"9-202407","status":"affected"},{"version":"9-202410","status":"affected"},{"version":"9-202412","status":"affected"},{"version":"9-202501","status":"affected"},{"version":"9-202502","status":"affected"},{"version":"9-202504","status":"affected"},{"version":"9-202507","status":"affected"},{"version":"9-202510","status":"affected"},{"version":"9-202601","status":"affected"},{"version":"10-202606","status":"affected"}],"defaultStatus":"unknown"}],"providerMetadata":{"orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco","dateUpdated":"2026-10-07T16:12:31.265Z"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-10-07T16:53:51.176135Z","id":"CVE-2026-76454","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-07T16:54:07.562Z"}}]}}