# Cisco License On-Prem flaws enable root takeover

Published: 2026-10-08 · Severity: routine
Canonical: https://vorant.io/reports/61c97c02-3c4f-55ff-833a-066c5570f09a/cisco-license-on-prem-flaws-enable-root-takeover

> Cisco patched eight vulnerabilities in License On-Prem, including a CVSS 10.0 flaw letting unauthenticated attackers reset passwords or execute root commands.

NCSC-NL published an advisory describing eight vulnerabilities fixed by Cisco in its License On-Prem product, affecting the web-based management interface and API endpoints. The flaws span multiple weakness classes: relative path traversal, OS command injection, SQL injection, missing authorization, code injection, missing authentication for a critical function, improper verification of cryptographic signatures, and insufficiently protected credentials.

Unauthenticated attackers can exploit several of these issues to reset passwords, write arbitrary files, or cause denial-of-service conditions. Authenticated attackers with administrator privileges can escalate further, executing arbitrary commands with root privileges and leveraging SQL injection to access internal database contents. Collectively the flaws threaten confidentiality, integrity and availability of affected deployments. CVSS scores range up to 10.0, with several in the critical (9.1-10.0) and high (8.8) range.

Cisco has released updates addressing all eight CVEs. NCSC-NL advises against exposing the License On-Prem management interface or API publicly, and recommends isolating such interfaces in separate management networks with additional access controls even on internal networks. No evidence of active in-the-wild exploitation is mentioned in the advisory; defenders should prioritize patching given the severity and remote unauthenticated attack vectors.

## Mentioned in this report

- Vulnerabilities: CVE-2026-20328, CVE-2026-76437, CVE-2026-76452, CVE-2026-76454, CVE-2026-76480, CVE-2026-76482, CVE-2026-76483, CVE-2026-76484

## Detection guidance (public sample)

### Web Server or App Runtime Spawning Shell with Download or Reverse-Shell Commands

ATT&CK: T1059

Detects a web server or application runtime process on Linux spawning a shell that runs download, staging or reverse-shell commands, as seen after OS command injection in a web management interface. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Web Server or App Runtime Spawning Shell with Download or Reverse-Shell Commands
description: Detects web server or application runtime processes (nginx, httpd, apache2,
  gunicorn, uwsgi, java, python, php-fpm, node) spawning a shell with -c and download,
  staging or reverse-shell content. Typical post-exploitation of OS command injection
  in appliance web UIs and APIs, including those running with root privileges.
tags:
- attack.execution
- attack.t1059
- attack.initial-access
- attack.t1190
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
    - /nginx
    - /httpd
    - /apache2
    - /gunicorn
    - /uwsgi
    - /java
    - /php-fpm
    - /node
    - /python
    - /python3
  selection_shell:
    Image|endswith:
    - /sh
    - /bash
    - /dash
    CommandLine|contains: ' -c'
  selection_payload:
    CommandLine|contains:
    - curl
    - wget
    - /dev/tcp/
    - mkfifo
    - 'nc '
    - ncat
    - base64 -d
    - chmod +x
    - chmod 777
  condition: selection_parent and selection_shell and selection_payload
falsepositives:
- Appliance health-check or update scripts that call curl from a Python or Java service
  wrapper
- Application deployment hooks that download artifacts via a shell from the app runtime
level: medium
id: ac0bf0c8-9270-53ec-aa9d-6ea6e2f67fb6
status: experimental
author: Vorant
references:
- https://advisories.ncsc.nl/2026/ncsc-2026-0407.html
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0407.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/61c97c02-3c4f-55ff-833a-066c5570f09a/cisco-license-on-prem-flaws-enable-root-takeover.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
