CVE-2026-20121: Improper Access Control in Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.
AI Analysis
Technical Summary
This vulnerability arises from a logic error in how group access control policies (ACPs) are populated when Object Group Search (OGS) is configured in Cisco Secure Firewall ASA and FTD Software. The flaw allows an unauthenticated remote attacker to bypass access controls by sending traffic that should be blocked, effectively circumventing the ACL protections. The issue affects multiple specific versions of Cisco ASA Software, and an official patch has been released to address the problem.
Potential Impact
Successful exploitation allows an unauthenticated remote attacker to bypass configured access controls on the firewall, potentially enabling unauthorized network traffic to reach protected devices. This could undermine network segmentation and security policies but does not directly impact confidentiality or availability according to the CVSS vector.
Mitigation Recommendations
An official fix is available from Cisco for this vulnerability. Users should apply the vendor-provided patches to affected versions of Cisco Secure Firewall ASA and FTD Software to remediate the issue. No additional mitigation actions are indicated beyond applying the official fix.
CVE-2026-20121: Improper Access Control in Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
Description
A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.
CVSS v3.1
Score 5.3medium
Affected software
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
Cisco
Cisco Secure Firewall Threat Defense (FTD) Software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from a logic error in how group access control policies (ACPs) are populated when Object Group Search (OGS) is configured in Cisco Secure Firewall ASA and FTD Software. The flaw allows an unauthenticated remote attacker to bypass access controls by sending traffic that should be blocked, effectively circumventing the ACL protections. The issue affects multiple specific versions of Cisco ASA Software, and an official patch has been released to address the problem.
Potential Impact
Successful exploitation allows an unauthenticated remote attacker to bypass configured access controls on the firewall, potentially enabling unauthorized network traffic to reach protected devices. This could undermine network segmentation and security policies but does not directly impact confidentiality or availability according to the CVSS vector.
Mitigation Recommendations
An official fix is available from Cisco for this vulnerability. Users should apply the vendor-provided patches to affected versions of Cisco Secure Firewall ASA and FTD Software to remediate the issue. No additional mitigation actions are indicated beyond applying the official fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cisco
- Date Reserved
- 2025-10-08T11:59:15.377Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- official-fix
Threat ID: 6aab005e55bf5e2cf5231de8
Added to database: 09/16/2026, 20:47:26 UTC
Last enriched: 09/16/2026, 22:02:24 UTC
Last updated: 09/17/2026, 05:01:23 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.