• News/
  • https://www.bleepingcomputer.com/news/security/critical-cisco-imc-auth-bypass-gives-attackers-admin-access/

Critical Cisco IMC auth bypass gives attackers Admin access

BleepingComputer
·
Sergiu Gatlan
·
Published Apr 2, 2026
·
Updated

Cisco has released security updates to address several critical and high-severity vulnerabilities, including an Integrated Management Controller (IMC) authentication bypass that allows attackers to gain Admin access. Also known as CIMC, Cisco IMC is a hardware module embedded on the motherboard of Cisco servers that provides out-of-band management (even if the operating system is powered off or crashed) for UCS C-Series and E-Series servers via multiple interfaces, including XML API, web (WebUI), and command-line (CLI). Tracked as CVE-2026-20093, the vulnerability was found in the Cisco IMC password change functionality and can be remotely exploited by unauthenticated attackers to bypass authentication and access unpatched systems with Admin privileges. "This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device," Cisco explained on Wednesday. "A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user." While Cisco's Product Security Incident Response Team (PSIRT) has yet to find evidence of in-the-wild exploitation or a proof-of-concept exploit code, the company "strongly recommends that customers upgrade to the fixed software" as there are no workarounds to temporarily mitigate this security flaw. This week, Cisco has also releas...

Read full article

Affected Software

3 affected components
Cisco Integrated Management Controller (IMC)
Cisco Smart Software Manager On-Prem (SSM On-Prem)
Cisco Secure Firewall Management Center (FMC)

Frequently Asked Questions

1

What is the main vulnerability discussed in this article?

The article discusses a critical authentication bypass vulnerability in Cisco's Integrated Management Controller (IMC) that allows attackers to gain Admin access.

2

What security updates has Cisco released in relation to these vulnerabilities?

Cisco released updates to address several critical and high-severity vulnerabilities, including the IMC authentication bypass.

3

Which Cisco products are affected by the authentication bypass vulnerability?

The affected products include Cisco Integrated Management Controller (IMC), Cisco Smart Software Manager On-Prem, and Cisco Secure Firewall Management Center.

4

What are the potential risks associated with the IMC authentication bypass?

The vulnerability poses a risk of unauthorized access, potentially allowing attackers to control critical hardware and configurations.

5

Is this vulnerability currently being exploited?

Yes, the vulnerability has been marked as exploited and is categorized as a zero-day threat.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203