CVE-2026-20288
Received Received - Intake

Command Injection in Cisco IMC Web Interface

Vulnerability report for CVE-2026-20288, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.  Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cisco imc *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-146 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as expression or command delimiters when they are sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected Cisco IMC system and escalate privileges to root. It is caused by improper validation of user-supplied input in the web-based management interface.

Detection Guidance

Detecting this vulnerability requires checking for vulnerable versions of Cisco IMC and monitoring for unauthorized command execution. Inspect installed Cisco IMC software versions and compare them against Cisco's advisory for affected releases. Monitor system logs for unusual commands executed via the web interface, especially those originating from authenticated Admin users.

Impact Analysis

An attacker could gain full control over the affected system, execute malicious commands, and access sensitive data. Since privileges escalate to root, the attacker could take complete control of the system.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating compliance requirements such as GDPR and HIPAA. Full system compromise may result in data exposure and regulatory penalties.

Mitigation Strategies

Immediately update Cisco IMC to the latest patched version provided by Cisco. Restrict Admin-level access to the web-based management interface to trusted users only. Monitor network traffic for unusual commands or activity from the interface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20288. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart