A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco
Cisco unified Computing System Cisco unified Computing System Software |
|
| Vendors & Products |
Cisco
Cisco unified Computing System Cisco unified Computing System Software |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. | |
| Title | Cisco Integrated Management Controller Command Injection Vulnerability | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisco
Published: 2026-04-01T16:28:50.641Z
Updated: 2026-04-02T03:56:15.176Z
Reserved: 2025-10-08T11:59:15.369Z
Link: CVE-2026-20094
Updated: 2026-04-01T18:17:23.337Z
Status : Awaiting Analysis
Published: 2026-04-01T17:28:29.230
Modified: 2026-04-03T16:11:11.357
Link: CVE-2026-20094
No data.