Command Execution Vulnerability in Cisco Integrated Management Controller
CVE-2026-20288

6.5MEDIUM

What is CVE-2026-20288?

A vulnerability exists in the web-based management interface of Cisco's Integrated Management Controller (IMC) that could allow an authenticated remote attacker with administrative privileges to execute arbitrary commands on the underlying operating system. This flaw arises from inadequate validation of user-supplied input, enabling potential exploitation through crafted input. Such an exploit could permit the attacker to execute commands as the root user, leading to elevated privileges and significant security ramifications.

Affected Version(s)

Cisco Unified Computing System (Standalone) 4.0(2g)

Cisco Unified Computing System (Standalone) 3.1(2i)

Cisco Unified Computing System (Standalone) 3.1(1d)

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.