Command Injection Vulnerability in Cisco IMC Web Management Interface
CVE-2026-20094
8.8HIGH
What is CVE-2026-20094?
A remote attacker with read-only access can exploit a vulnerability in the web-based management interface of Cisco IMC. By sending specially crafted commands, the attacker may perform command injection attacks, compromising the system's integrity. This flaw stems from inadequate validation of user-supplied input, allowing malicious commands to be executed as the root user. Security measures must be taken to mitigate the risks associated with this vulnerability.
Affected Version(s)
Cisco Unified Computing System (Standalone) 4.0(2g)
Cisco Unified Computing System (Standalone) 3.1(2i)
Cisco Unified Computing System (Standalone) 3.1(1d)