Description
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. 

This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. 
Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.
Published: 2026-08-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the web‑based management interface of Cisco IMC allows an authenticated attacker with administrative privilege to inject malicious input that is not properly validated. Successful exploitation gives the attacker the ability to run arbitrary commands on the host operating system with root privileges, leading to full compromise of the affected device. The vulnerability is classified as CWE‑146, reflecting the failure to properly encode or validate user input.

Affected Systems

The affected products are Cisco Unified Computing System (Standalone) and Cisco Unified Computing System E‑Series Software (UCSE). No specific version numbers are supplied in the advisory, so all current or older versions of these products should be assessed for the presence of the vulnerability.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate‑to‑high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests that it has not yet been widely observed in the wild. However, the attack requires the attacker to be authenticated with Admin privileges, so the risk is contingent on privileged access. If an attacker gains such access, they can elevate to root and execute arbitrary code on the underlying system. The advisory notes that the SIR is High because of the potential for root-level compromise, so an effective risk is the possibility of a full system takeover by a authenticated adversary.

Generated by OpenCVE AI on August 5, 2026 at 18:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Cisco IMC firmware update that resolves the input validation flaw.
  • Restrict access to the IMC web interface to trusted administrators only, using network segmentation or firewall rules.
  • Enforce least privilege for accounts that manage IMC; avoid using Admin rights for routine management tasks.

Generated by OpenCVE AI on August 5, 2026 at 18:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco cisco Unified Computing System E-series Software
Cisco unified Computing System Manager
Vendors & Products Cisco
Cisco cisco Unified Computing System E-series Software
Cisco unified Computing System Manager

Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with&nbsp;Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbsp; This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.&nbsp; Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes&nbsp;root.
Title Cisco IMC Remote Code Execution Vulnerability Remote Code Execution Vulnerability
Weaknesses CWE-146
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Cisco Cisco Unified Computing System E-series Software Unified Computing System Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-06T03:55:30.370Z

Reserved: 2025-10-08T11:59:15.405Z

Link: CVE-2026-20288

cve-icon Vulnrichment

Updated: 2026-08-05T17:39:03.361Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-05T17:16:49.527

Modified: 2026-08-06T15:44:56.043

Link: CVE-2026-20288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:53Z

Weaknesses
  • CWE-146

    Improper Neutralization of Expression/Command Delimiters