Command Injection Vulnerability in Cisco IMC Web Management Interface
CVE-2026-20094

8.8HIGH

What is CVE-2026-20094?

A remote attacker with read-only access can exploit a vulnerability in the web-based management interface of Cisco IMC. By sending specially crafted commands, the attacker may perform command injection attacks, compromising the system's integrity. This flaw stems from inadequate validation of user-supplied input, allowing malicious commands to be executed as the root user. Security measures must be taken to mitigate the risks associated with this vulnerability.

Affected Version(s)

Cisco Unified Computing System (Standalone) 4.0(2g)

Cisco Unified Computing System (Standalone) 3.1(2i)

Cisco Unified Computing System (Standalone) 3.1(1d)

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.