This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.
Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 07 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco
Cisco cisco Unified Computing System E-series Software Cisco unified Computing System Manager |
|
| Vendors & Products |
Cisco
Cisco cisco Unified Computing System E-series Software Cisco unified Computing System Manager |
Wed, 05 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root. | |
| Title | Cisco IMC Remote Code Execution Vulnerability Remote Code Execution Vulnerability | |
| Weaknesses | CWE-146 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2026-08-06T03:55:30.370Z
Reserved: 2025-10-08T11:59:15.405Z
Link: CVE-2026-20288
Updated: 2026-08-05T17:39:03.361Z
Status : Awaiting Analysis
Published: 2026-08-05T17:16:49.527
Modified: 2026-08-06T15:44:56.043
Link: CVE-2026-20288
No data.
OpenCVE Enrichment
Updated: 2026-08-07T10:05:53Z