Cisco Smart Software Manager On-Prem (SSM On-Prem) suffers two distinct vulnerabilities. One allows authenticated users with System User roles to extract session credentials via the web interface and escalate to administrative privileges. The other exposes an internal API service that unauthenticated attackers can exploit to execute arbitrary commands as root on the host system. These flaws together mean attackers can gain full control either by escalating privileges from a low-level account or by exploiting the unauthenticated API. No workarounds exist; only software updates fully fix both issues. Operators must patch immediately and assume potential compromise of admin credentials and root access. Incident response should include credential rotation and host integrity verification.
Part of the PlainSec briefing for 2026-04-02