Junglewise Threat Intelligence

CVE-2026-20288: Cisco Integrated Management Controller argument injection in web interface

CVE-2026-20288 · Severity: medium · CVSS 6.5 · Published 2026-08-05

Technologies: Cisco Catalyst 8300 Series Edge uCPE, Cisco UCS S-Series Storage Servers. Vendors: Cisco.

Executive brief

Cisco's Integrated Management Controller (IMC) is a web-based management interface for server hardware that allows administrators to remotely monitor and configure systems. An authenticated attacker with administrative privileges can inject arbitrary commands through crafted web interface inputs, leading to remote code execution and privilege escalation to root. This undermines the security of critical infrastructure including data center servers, edge appliances, and enterprise network systems.

Technical details

This is an argument injection vulnerability (CWE-141, CWE-146) in the web-based management interface of Cisco IMC due to improper validation of user-supplied input. An authenticated, remote attacker with Admin privileges can enter crafted inputs to the web interface to execute arbitrary commands on the underlying operating system as the root user. The vulnerability is network-accessible and requires valid admin credentials but no user interaction. Successful exploitation allows complete system compromise including data access, integrity violation, and service disruption. Cisco has released software updates to address this vulnerability; no workarounds are available.

Affected products

  • Cisco 5000 Series Enterprise Network Compute Systems (ENCS)
  • Cisco Catalyst 8300 Series Edge uCPE
  • Cisco UCS C-Series M5 and M6 Rack Servers
  • Cisco UCS C-Series M7 and M8 Rack Servers
  • Cisco UCS E-Series Servers M3
  • Cisco UCS E-Series Servers M6
  • Cisco UCS S-Series Storage Servers
  • Cisco Application Policy Infrastructure Controller (APIC) Servers
  • Cisco Business Edition 6000 and 7000 Appliances
  • Cisco Catalyst Center Appliances
  • Cisco Telemetry Broker Appliances
  • Cisco Cloud Services Platform (CSP) 5000 Series
  • Cisco Cyber Vision Center Appliances
  • Cisco HyperFlex Edge Nodes
  • Cisco HyperFlex Nodes
  • Cisco Nexus Dashboard Appliances
  • Cisco Secure Firewall Management Center (FMC) Appliances
  • Cisco IOS XRv 9000 Appliances

Timeline

  • 2026-08-05: disclosed
  • 2026-08-05: advisory: Cisco Security Advisory published

References

Related threats