CVE-2026-20094 Details
Description
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.
A command injection vulnerability has been identified in the web-based management interface of Cisco Integrated Management Controller (IMC). This vulnerability allows an authenticated, remote attacker with read-only privileges to execute arbitrary commands on the underlying operating system as the root user. The issue arises from improper validation of user-supplied input, enabling attackers to send crafted commands that are executed with elevated privileges.
Cisco has released software updates to address this vulnerability. For Cisco 5000 Series ENCS and Catalyst 8300 Series Edge uCPE, the IMC upgrade is part of the firmware auto-upgrade process. UCS C-Series M5 and M6 Rack Servers can be upgraded to specific fixed releases. For UCS E-Series Servers, similar upgrade paths are available. Instructions for upgrading Cisco IMC on appliances based on a preconfigured version of a Cisco UCS C-Series Server are also provided in the advisory.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-3hKN3bVt | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco unified computing system | 3.1(1d) 3.1(2b) 3.1(2c) 3.1(2d) 3.1(2e) 3.1(2g) 3.1(2i) 3.1(3a) 3.1(3b) 3.1(3c) 3.1(3d) 3.1(3g) 3.1(3h) 3.1(3i) 3.1(3j) 3.1(3k) 4.0(1.240) 4.0(1a) 4.0(1b) 4.0(1c) 4.0(1d) 4.0(1e) 4.0(1g) 4.0(1h) 4.0(2c) 4.0(2d) 4.0(2f) 4.0(2g) 4.0(2h) 4.0(2i) 4.0(2k) 4.0(2l) 4.0(2m) 4.0(2n) 4.0(2o) 4.0(2p) 4.0(2q) 4.0(2r) 4.0(4b) 4.0(4c) 4.0(4d) 4.0(4e) 4.0(4f) 4.0(4h) 4.0(4i) 4.0(4j) 4.0(4k) 4.0(4l) 4.0(4m) 4.0(4n) 4.1(1c) 4.1(1d) 4.1(1f) 4.1(1g) 4.1(1h) 4.1(2a) 4.1(2b) 4.1(2d) 4.1(2e) 4.1(2f) 4.1(2g) 4.1(2h) 4.1(2j) 4.1(2k) 4.1(2l) 4.1(2m) 4.1(3b) 4.1(3c) 4.1(3d) 4.1(3f) 4.1(3g) 4.1(3h) 4.1(3i) 4.1(3l) 4.1(3m) 4.1(3n) 4.2(1a) 4.2(1b) 4.2(1c) 4.2(1e) 4.2(1f) 4.2(1g) 4.2(1i) 4.2(1j) 4.2(2a) 4.2(2f) 4.2(2g) 4.2(3b) 4.2(3d) 4.2(3e) 4.2(3g) 4.2(3h) 4.2(3i) 4.2(3j) 4.2(3k) 4.2(3l) 4.2(3m) 4.2(3n) 4.2(3o) 4.2(3p) 4.3(1.230097) 4.3(1.230124) 4.3(1.230138) 4.3(2.230207) 4.3(2.230270) 4.3(2.240002) 4.3(2.240009) 4.3(2.240037) 4.3(2.240053) 4.3(2.240077) 4.3(2.240090) 4.3(2.240107) 4.3(2.250016) 4.3(2.250021) 4.3(2.250022) 4.3(2.250037) 4.3(2.250045) 4.3(2.250063) 4.3(3.240022) 4.3(3.240041) 4.3(3.240043) 4.3(4.240142) 4.3(4.240152) 4.3(4.241014) 4.3(4.241063) 4.3(4.242028) 4.3(4.242038) 4.3(4.242066) 4.3(4.252001) 4.3(4.252002) 4.3(5.240021) 4.3(5.250001) 4.3(5.250030) 4.3(5.250033) 4.3(5.250043) 4.3(5.250045) 4.3(6.250039) 4.3(6.250040) 4.3(6.250044) 4.3(6.250053) 4.3(6.250060) 4.3(6.250101) 4.3(6.250117) 4.3(6.260003) 6.0(1.250127) 6.0(1.250130) 6.0(1.250131) 6.0(1.250174) 6.0(1.250192) 6.0(1.250194) |
CPE
Remediation
| |
| cisco unified computing system e-series software | 2.0.0 2.1.0 2.2.1 2.2.2 2.3.1 2.3.2 2.3.3 2.3.5 2.4.0 2.4.1 2.4.2 3.0.1 3.0.2 3.1.0 3.1.1 3.1.2 3.1.3 3.1.4 3.1.5 3.2.1 3.2.2 3.2.3 3.2.4 3.2.6 3.2.7 3.2.8 3.2.10 3.2.11.1 3.2.11.3 3.2.11.5 3.2.12.2 3.2.13.6 3.2.14 3.2.15 3.2.15.3 3.2.16.1 4.00 4.02 4.11.1 4.12.1 4.12.2 4.15.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 28, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2026 | New CVE Received | [email protected] |