Cisco Secure Firewall Management Center and Threat Defense Software path traversal enables root file writes

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-20018?

CVE-2026-20018 is a vulnerability classified as Path Traversal: 'dir/../../filename', affecting Cisco Secure Firewall Management Center (FMC) (affected versions: 7.0.0, 7.0.0.1, and other affected versions) and Cisco Secure Firewall Threat Defense (FTD) Software (affected versions: 7.0.0, 7.0.0.1, and other affected versions). This vulnerability is rated Medium, with a CVSS score of 5.9. Current sources do not report this vulnerability as exploited.

Overview

Original source data

A vulnerability in the sftunnel functionality of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrative privileges to write arbitrary files as root on the underlying operating system. This vulnerability is due to insufficient validation of the directory path during file synchronization. An attacker could exploit this vulnerability by crafting a directory path outside of the expected file location. A successful exploit could allow the attacker to create or replace any file on the underlying operating system.

Affected products and scope

  • Cisco Secure Firewall Management Center (FMC) Software: the following versions are recorded as affected: 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3, 7.0.4, 7.0.5, 7.1.0, 7.1.0.1, 7.1.0.2, 7.1.0.3, 7.2.0, 7.2.0.1, 7.2.1, 7.2.2, 7.2.3, 7.3.0, and 7.3.1.
  • Cisco Secure Firewall Threat Defense (FTD) Software: the following versions are recorded as affected: 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3, 7.0.4, 7.0.5, 7.1.0, 7.1.0.1, 7.1.0.2, 7.1.0.3, 7.2.0, 7.2.0.1, 7.2.1, 7.2.2, 7.2.3, 7.3.0, and 7.3.1.
  • Cisco states that devices running an affected release are vulnerable regardless of device configuration. Cisco Secure Firewall Adaptive Security Appliance (ASA) Software is confirmed not affected.
  • The supplied record does not state exact fixed-release boundaries for FMC or FTD. The status of versions not listed remains unknown from this evidence.

Technical details

The vulnerability is in the sftunnel functionality used for file synchronization by Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software. Insufficient directory-path validation allows an attacker to supply a path outside the expected file location, creating a CWE-27 path traversal condition. The confirmed precondition is a remote attacker who is authenticated and has administrative privileges; no additional user interaction is required. If exploited successfully, the write operation runs as root, allowing arbitrary files on the underlying operating system to be created or replaced. The available evidence does not identify the specific endpoint, path syntax, target files, log event, or any subsequent code-execution capability.

Exploitability

The vulnerability is remotely reachable by an authenticated attacker with administrative privileges on FMC or FTD. No other user's interaction is required, but exploitation requires high privileges and a complex condition because the attacker must access the relevant sftunnel file-synchronization functionality with the necessary administrative rights. Cisco PSIRT states that it is not aware of public announcements or malicious use of the vulnerability described in the advisory. That statement does not prove that exploitation has not occurred outside Cisco's visibility. Cisco says the vulnerability was found during internal security testing.

Technical impact

Successful exploitation allows an attacker to write as root and create or replace any file on the underlying operating system. The direct technical consequence is loss of file integrity; device outage or malfunction is possible if a critical file is replaced. Organisational consequences could include disruption of management or defense traffic, changes to security policy enforcement, and device-recovery effort. The administrative-privilege requirement reduces exposure to users without that access, but it does not reduce the consequences once the privilege is abused. The available evidence does not describe arbitrary file reading, code execution, or a specific compromise.

Business impact

The vulnerability permits changes to files on the underlying operating system with root privileges, creating a serious integrity risk for management and network-defense appliances. Replacing system or configuration files could, depending on the targeted file, interrupt services, alter security behavior, or require device recovery. Because exploitation requires an authenticated administrative account, exposure is constrained by administrative access, but misuse of such an account could have substantial operational consequences. The available description does not confirm arbitrary file reads or a specific incident.

Remediation

  1. Upgrade FMC and FTD to a Cisco-confirmed fixed release. The supplied record and inspected advisory do not state exact fixed-version numbers for each branch, so use Cisco Software Checker to identify the first fixed release for every deployed version.
  2. Cisco states that no workaround addresses this vulnerability. Do not treat ordinary configuration changes as a substitute for upgrading.
  3. Before upgrading, inventory remotely accessible administrative accounts and remove unnecessary administrative access. This reduces exposure but does not remove the vulnerability.
  4. After upgrading, verify the actual software version on every device, check the integrity of important files, and continue reviewing unusual administrative activity.

Detection

  1. Inventory every device running Cisco Secure Firewall Management Center Software or Cisco Secure Firewall Threat Defense Software, then compare deployed versions with the affected versions listed below.
  2. Use Cisco Software Checker to determine which devices are affected and the first fixed release for each product branch.
  3. Review administrative authentication and administrative activity related to sftunnel or file synchronization. This is a precautionary review; the available record does not provide a named log event or a known IOC.
  4. Check the integrity of critical operating-system and configuration files against trusted baselines, looking for unexpected file creation or replacement. Do not treat the absence of log evidence as proof that a device is safe.
Sources (12)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan