Multiple security vulnerabilities have been identified in Cisco Integrated Management Controller (IMC) web-based management interface...
CVE-2026-20200 (CVSS 8.8 — High): An authenticated, remote attacker can execute arbitrary commands on the underlying operating system and elevate privileges to root.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in Cisco Integrated Management Controller (IMC) web-based management interface...
CVE-2026-20200 (CVSS 8.8 — High): An authenticated, remote attacker can execute arbitrary commands on the underlying operating system and elevate privileges to root.[emaillocker id="1283"]
CVE-2026-20288 (CVSS 8.8 — High): An authenticated, remote attacker can execute arbitrary commands on the underlying operating system and elevate privileges to root. These vulnerabilities collectively present a significant risk to administrators who have not applied updates, particularly those with direct access to the web-based management interface. These vulnerabilities collectively present a significant risk to administrators who have not applied updates, particularly those with direct access to the web-based management interface.
These vulnerabilities collectively present a significant risk to administrators who have not applied updates, particularly those with direct access to the web-based management interface.
We recommend you to update Cisco IMC to given version link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Integrated%20Management%20Controller%20Argument%20Injection%20Vulnerabilities%26vs_k=1
The following reports contain further technical details:
[/emaillocker]