CVE-2026-20288 Details
Description
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.
A vulnerability exists in the web-based management interface of Cisco Integrated Management Controller (IMC) that could enable an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system and elevate those privileges to root. This issue arises from improper validation of user-supplied input, allowing crafted inputs to be exploited. A successful exploitation would result in executing commands as the root user on the affected system.
Cisco has released software updates to address this vulnerability. For Cisco 5000 Series ENCS and Catalyst 8300 Series Edge uCPE, upgrading Cisco IMC requires updating Cisco Enterprise NFV Infrastructure Software (NFVIS) on the platforms. For UCS C-Series M6 Rack Servers, the vulnerability can be fixed by upgrading to version 6.0(2.260143) or 4.3(6.260054). Instructions for upgrading can be found in the Cisco Host Upgrade Utility User Guide.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-146 | Improper Neutralization of Expression/Command Delimiters | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco unified computing system | 3.1(1d) 3.1(2b) 3.1(2c) 3.1(2d) 3.1(2e) 3.1(2g) 3.1(2i) 3.1(3a) 3.1(3b) 3.1(3c) 3.1(3d) 3.1(3g) 3.1(3h) 3.1(3i) 3.1(3j) 3.1(3k) 4.0(1.240) 4.0(1a) 4.0(1b) 4.0(1c) 4.0(1d) 4.0(1e) 4.0(1g) 4.0(1h) 4.0(2c) 4.0(2d) 4.0(2f) 4.0(2g) 4.0(2h) 4.0(2i) 4.0(2k) 4.0(2l) 4.0(2m) 4.0(2n) 4.0(2o) 4.0(2p) 4.0(2q) 4.0(2r) 4.0(4b) 4.0(4c) 4.0(4d) 4.0(4e) 4.0(4f) 4.0(4h) 4.0(4i) 4.0(4j) 4.0(4k) 4.0(4l) 4.0(4m) 4.0(4n) 4.1(1c) 4.1(1d) 4.1(1f) 4.1(1g) 4.1(1h) 4.1(2a) 4.1(2b) 4.1(2d) 4.1(2e) 4.1(2f) 4.1(2g) 4.1(2h) 4.1(2j) 4.1(2k) 4.1(2l) 4.1(2m) 4.1(3b) 4.1(3c) 4.1(3d) 4.1(3f) 4.1(3g) 4.1(3h) 4.1(3i) 4.1(3l) 4.1(3m) 4.1(3n) 4.2(1a) 4.2(1b) 4.2(1c) 4.2(1e) 4.2(1f) 4.2(1g) 4.2(1i) 4.2(1j) 4.2(2a) 4.2(2f) 4.2(2g) 4.2(3b) 4.2(3d) 4.2(3e) 4.2(3g) 4.2(3h) 4.2(3i) 4.2(3j) 4.2(3k) 4.2(3l) 4.2(3m) 4.2(3n) 4.2(3o) 4.2(3p) 4.2(3q) 4.3(1.230097) 4.3(1.230124) 4.3(1.230138) 4.3(2.230207) 4.3(2.230270) 4.3(2.240002) 4.3(2.240009) 4.3(2.240037) 4.3(2.240053) 4.3(2.240077) 4.3(2.240090) 4.3(2.240107) 4.3(2.250016) 4.3(2.250021) 4.3(2.250022) 4.3(2.250037) 4.3(2.250045) 4.3(2.250063) 4.3(2.260007) 4.3(3.240022) 4.3(3.240041) 4.3(3.240043) 4.3(4.240142) 4.3(4.240152) 4.3(4.241014) 4.3(4.241063) 4.3(4.242028) 4.3(4.242038) 4.3(4.242066) 4.3(4.252001) 4.3(4.252002) 4.3(5.240021) 4.3(5.250001) 4.3(5.250030) 4.3(5.250033) 4.3(5.250043) 4.3(5.250045) 4.3(6.250039) 4.3(6.250040) 4.3(6.250044) 4.3(6.250053) 4.3(6.250060) 4.3(6.250101) 4.3(6.250117) 4.3(6.260003) 4.3(6.260017) 4.3(6.260033) 6.0(1.250127) 6.0(1.250130) 6.0(1.250131) 6.0(1.250174) 6.0(1.250192) 6.0(1.250194) 6.0(2.260044) 6.0(2.260069) |
CPE
Remediation
| |
| cisco unified computing system e-series software | 3.1.0 3.1.1 3.1.2 3.1.3 3.1.4 3.1.5 3.2.1 3.2.2 3.2.3 3.2.4 3.2.6 3.2.7 3.2.8 3.2.10 3.2.11.1 3.2.11.3 3.2.11.5 3.2.12.2 3.2.13.6 3.2.14 3.2.15 3.2.15.3 3.2.16.1 3.2.17.1 4.11.1 4.12.1 4.12.2 4.15.2 4.15.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | Initial Analysis | [email protected] |
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |