CVE-2026-20151 is a high-severity privilege escalation vulnerability found in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem). An authenticated, remote attacker with at least System User credentials can exploit improper transmission of sensitive user information. By sending a crafted message, the attacker can retrieve session credentials from subsequent status messages, allowing them to elevate their privileges from a low-level user to administrative on the affected system. Rated 7.3 HIGH on the CVSS scale, this vulnerability has low attack complexity but requires prior authentication and only affects users currently logged in via the web interface. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9-202601CPE matchmatch criteria | cpe:2.3:a:cisco:smart_software_manager_on-prem:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.