medium · CVSS v3 5.3
CVE-2026-20121
CVE‑2026‑20121 is a logic flaw in Cisco Secure Firewall ASA and FTD that lets an unauthenticated remote attacker bypass configured ACLs by m
Overview
CVE‑2026‑20121 is a logic flaw in Cisco Secure Firewall ASA and FTD that lets an unauthenticated remote attacker bypass configured ACLs by manipulating Object Group Search (OGS). The flaw can be triggered by crafted traffic that should be blocked, allowing the attacker to reach protected network resources. It does not require authentication or privileged access to the device.
Description
A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.
Impact
The vulnerability permits unauthorized network access, compromising confidentiality by exposing internal hosts, potentially affecting integrity if the attacker can modify traffic, and availability if the attacker floods the device with bypassed traffic. Defenders should treat it as a risk to network segmentation and internal asset protection.
Remediation
['Apply the latest Cisco ASA and FTD firmware or patch that addresses CVE‑2026‑20121.', 'If a patch is not immediately available, disable or restrict Object Group Search (OGS) functionality or remove OGS‑based ACL entries until a fix is deployed.', 'Verify ACL configurations to ensure they do not rely on OGS for critical access decisions.', 'Enable logging for ACL violations and monitor logs for unexpected traffic patterns.', 'Maintain an up‑to‑date inventory of firewall firmware versions and schedule regular vulnerability scans.']
Risk context
The CVSS v3 score of 5.3 classifies this as medium severity. No EPSS data is available, but the flaw allows remote bypass of ACLs without authentication, making it a significant threat to network segmentation. Prompt patching or mitigation is recommended to prevent potential lateral movement.
Affected products
- Cisco Secure Firewall ASA
- Cisco Secure Firewall FTD
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- —