H3-2026-0010¶
Cisco Secure Firewall Management Center Session Fixation Vulnerability
| Category | VULNERABILITY |
| Base Score | 8.9 |
Description¶
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted system. The vulnerability is due to the presence of static user credentials for a low-privileged account.
Impact¶
Remote unauthenticated attackers can log in with static low-privileged credentials to access sensitive data on the FMC host. Cisco notes this access can be combined with other FMC vulnerabilities to escalate privileges, though the credential exposure alone does not grant code execution.