cbcvebase.
CVE-2026-20093
published 2026-04-01

CVE-2026-20093: A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass…

PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.99%
58.6th percentile
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user.

Affected

253 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a crafted HTTP request targeting the IMC password change functionality; monitor for anomalous unauthenticated HTTP requests to Cisco IMC/CIMC web interfaces (WebUI) targeting password change endpoints
  • Alert on unexpected password change events for any user account (especially Admin) on Cisco IMC devices originating from unauthenticated or external sessions
  • Affected interfaces include XML API, WebUI, and CLI on UCS C-Series and E-Series servers; monitor all three management interfaces for suspicious unauthenticated access attempts
  • ·Vulnerability affects all listed products regardless of device configuration; no workaround exists — patching is the only mitigation
  • ·Fixed versions vary by product line: ENCS 5000 fixed in 4.15.5; Catalyst 8300 uCPE fixed in 4.18.3; UCS C-Series M5/M6 fixed in 4.3(2.260007), 4.3(6.260017), and 6.0(1.250174); UCS E-Series M3 fixed in 3.2.17; UCS E-Series M6 fixed in 4.15.3
  • ·Cisco internal bug IDs for tracking: CSCwq55648, CSCwq55659, CSCwq68912

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco3.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.