CVE-2026-20200
Received Received - Intake

Command Injection in Cisco IMC Web Interface

Vulnerability report for CVE-2026-20200, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. 

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
cisco imc *
cisco integrated_management_controller *
cisco ucs_c-series_m7_rack_server *
cisco ucs_c-series_m8_rack_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-141 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as parameter or argument delimiters when they are sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a high-severity vulnerability in Cisco IMC's web-based management interface. It allows an authenticated remote attacker with low privileges to execute arbitrary commands on the underlying operating system and escalate privileges to root. The issue arises from improper validation of user-supplied input, enabling crafted inputs to be injected through the web interface.

Detection Guidance

Detecting this vulnerability requires checking if your Cisco IMC version is affected and monitoring for unauthorized command execution. Review system logs for suspicious activity in the web-based management interface and verify if input validation is properly implemented. No specific commands are provided in the resources.

Impact Analysis

An attacker could gain root-level access to your system, allowing them to execute any command, steal data, install malware, or disrupt operations. Since the attack is remote and requires only low-privilege authentication, it poses a significant risk to affected Cisco IMC systems.

Compliance Impact

This vulnerability could lead to unauthorized access, data breaches, or loss of sensitive information, violating compliance requirements for GDPR, HIPAA, and other regulations. Root-level access may result in non-compliance with security controls and data protection mandates.

Mitigation Strategies

Immediately upgrade to the fixed software releases specified in Cisco's advisory. Since no workarounds are available, patching is the only mitigation. Monitor Cisco's security advisory for updates and apply patches as soon as possible to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20200. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart