Junglewise Threat Intelligence

CVE-2026-20200: Cisco IMC argument injection in web management interface

CVE-2026-20200 · Severity: high · CVSS 8.8 · Published 2026-08-05

Technologies: Cisco UCS S-Series Storage Servers, Cisco Catalyst 8300 Series Edge uCPE, Cisco Secure Firewall Management Center (FMC). Vendors: Cisco.

Executive brief

Cisco Integrated Management Controller (IMC) is a web-based management interface used to remotely manage Cisco servers and related appliances. An authenticated attacker with low privileges could exploit improper input validation to execute arbitrary commands as the root user, gaining full control of the underlying system. This affects many enterprise server and appliance models across Cisco's product portfolio.

Technical details

The vulnerability is an argument injection flaw (CWE-141/CWE-146) in the IMC web-based management interface caused by improper validation of user-supplied input. An authenticated remote attacker with low privileges can exploit this by submitting crafted input through the web interface to execute arbitrary operating system commands with root privileges. No user interaction is required beyond initial authentication, and the attack is network-reachable. Cisco has released software updates to address the vulnerability; no workarounds are available.

Affected products

  • Cisco UCS C-Series M7 and M8 Rack Servers See vendor advisory for specific vulnerable releases
  • Cisco UCS C-Series M5 and M6 Rack Servers See vendor advisory for specific vulnerable releases
  • Cisco Catalyst 8300 Series Edge uCPE See vendor advisory for specific vulnerable releases
  • Cisco 5000 Series Enterprise Network Compute Systems See vendor advisory for specific vulnerable releases
  • Cisco UCS E-Series Servers M3 See vendor advisory for specific vulnerable releases
  • Cisco UCS E-Series Servers M6 See vendor advisory for specific vulnerable releases
  • Cisco UCS S-Series Storage Servers See vendor advisory for specific vulnerable releases
  • Cisco Application Policy Infrastructure Controller (APIC) See vendor advisory for specific vulnerable releases
  • Cisco Catalyst Center Appliances See vendor advisory for specific vulnerable releases
  • Cisco Secure Firewall Management Center (FMC) See vendor advisory for specific vulnerable releases

Timeline

  • 2026-08-05: disclosed: Vulnerability publicly disclosed
  • 2026-08-05: advisory: Cisco Security Advisory cisco-sa-cimc-arg-inject-upSHdMfU published

References

Related threats