CVE-2026-20200: Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20200?
The severity of CVE-2026-20200 is rated as high with a CVSS score of 8.8.
How do I fix CVE-2026-20200?
To fix CVE-2026-20200, ensure that you upgrade to the latest Cisco IMC version as provided by Cisco.
What type of attacks can CVE-2026-20200 facilitate?
CVE-2026-20200 can facilitate arbitrary command execution and privilege escalation on affected systems.
Who is affected by CVE-2026-20200?
Authenticated remote attackers with low privileges can exploit CVE-2026-20200 on affected Cisco IMC systems.
What systems are impacted by CVE-2026-20200?
CVE-2026-20200 specifically impacts Cisco Integrated Management Controller (IMC) systems.