Description
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. 

This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. 
Published: 2026-08-05
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution with Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability in the Cisco Integrated Management Controller (IMC) web interface allows an authenticated, low‑privileged user to submit malicious arguments that the system forwards directly to the operating‑system command interpreter. A successful exploit gives the attacker the ability to run arbitrary commands with root privileges, effectively taking full control of the host.

Affected Systems

Affected devices are Cisco Unified Computing System (Standalone) models with IMC firmware versions listed in the CPE data, ranging from 4.3(1.230097) through 6.0(1.250194). All firmware iterations that have not yet received a security update to address the argument injection flaw are vulnerable.

Risk and Exploitability

The CVSS score of 8.8 classifies the flaw as high severity, and the EPSS score of <1% suggests a very low current exploitation probability. Because the flaw requires authentication, an attacker must first obtain a low‑privileged account, but the path to root is straightforward once the vulnerability is leveraged. The vulnerability is not currently in the CISA KEV catalog, indicating no publicly known exploits at this time.

Generated by OpenCVE AI on September 24, 2026 at 19:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Verify whether an official firmware patch or hotfix addressing the argument injection vulnerability is available on Cisco’s security advisory page and apply it to all affected devices.
  • Limit access to the IMC web interface to authorized administrators and disable or restrict low‑privileged accounts from performing management tasks.
  • Implement network segmentation and firewall rules to block external access to the IMC interface except from trusted management networks.

Generated by OpenCVE AI on September 24, 2026 at 19:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco unified Computing System
CPEs cpe:2.3:a:cisco:unified_computing_system:4.3\(1.230097\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(1.230124\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(1.230138\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(2.230207\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(2.230270\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(2.240002\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(3.240022\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(3.240043\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(4.240142\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(4.240152\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(4.241014\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(4.241063\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(4.242028\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(4.242038\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(4.242066\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(4.252001\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(4.252002\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(5.240021\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(5.250001\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(5.250030\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(5.250033\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(5.250043\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(5.250045\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(6.250039\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(6.250040\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(6.250044\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(6.250053\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(6.250060\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(6.250101\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(6.250117\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(6.260003\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:4.3\(6.260017\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:6.0\(1.250127\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:6.0\(1.250130\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:6.0\(1.250131\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:6.0\(1.250174\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:6.0\(1.250192\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_computing_system:6.0\(1.250194\):*:*:*:*:*:*:*
Vendors & Products Cisco unified Computing System

Fri, 07 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco unified Computing System Manager
Vendors & Products Cisco
Cisco unified Computing System Manager

Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbsp; This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.&nbsp;
Title Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability
Weaknesses CWE-141
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cisco Unified Computing System Unified Computing System Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-16T03:55:58.219Z

Reserved: 2025-10-08T11:59:15.397Z

Link: CVE-2026-20200

cve-icon Vulnrichment

Updated: 2026-08-05T17:30:49.309Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T17:16:47.180

Modified: 2026-08-31T20:35:43.247

Link: CVE-2026-20200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T19:15:15Z

Weaknesses
  • CWE-141

    Improper Neutralization of Parameter/Argument Delimiters