Command Execution Vulnerability in Cisco Integrated Management Controller
CVE-2026-20288
6.5MEDIUM
What is CVE-2026-20288?
A vulnerability exists in the web-based management interface of Cisco's Integrated Management Controller (IMC) that could allow an authenticated remote attacker with administrative privileges to execute arbitrary commands on the underlying operating system. This flaw arises from inadequate validation of user-supplied input, enabling potential exploitation through crafted input. Such an exploit could permit the attacker to execute commands as the root user, leading to elevated privileges and significant security ramifications.
Affected Version(s)
Cisco Unified Computing System (Standalone) 4.0(2g)
Cisco Unified Computing System (Standalone) 3.1(2i)
Cisco Unified Computing System (Standalone) 3.1(1d)