CVE-2026-20093
published 2026-04-01CVE-2026-20093: A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass…
PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.99%
58.6th percentile
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin.
This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user.
Affected
253 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
| cisco | cisco_enterprise_nfv_infrastructure_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is a crafted HTTP request targeting the IMC password change functionality; monitor for anomalous unauthenticated HTTP requests to Cisco IMC/CIMC web interfaces (WebUI) targeting password change endpoints ↗
- →Alert on unexpected password change events for any user account (especially Admin) on Cisco IMC devices originating from unauthenticated or external sessions ↗
- →Affected interfaces include XML API, WebUI, and CLI on UCS C-Series and E-Series servers; monitor all three management interfaces for suspicious unauthenticated access attempts ↗
- ·Vulnerability affects all listed products regardless of device configuration; no workaround exists — patching is the only mitigation ↗
- ·Fixed versions vary by product line: ENCS 5000 fixed in 4.15.5; Catalyst 8300 uCPE fixed in 4.18.3; UCS C-Series M5/M6 fixed in 4.3(2.260007), 4.3(6.260017), and 6.0(1.250174); UCS E-Series M3 fixed in 3.2.17; UCS E-Series M6 fixed in 4.15.3 ↗
- ·Cisco internal bug IDs for tracking: CSCwq55648, CSCwq55659, CSCwq68912 ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco3.1
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8gpv-wqhx-xp52: A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker t
ghsa_unreviewed·2026-04-01
CVE-2026-20093 [CRITICAL] CWE-20 GHSA-8gpv-wqhx-xp52: A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker t
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin.
This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user.
Cisco
Cisco Integrated Management Controller Authentication Bypass Vulnerability
vendor_cisco·CVSS 3.1
CVE-2026-20093 Cisco Integrated Management Controller Authentication Bypass Vulnerability
CVE-2026-20093: Cisco Integrated Management Controller Authentication Bypass Vulnerability
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin . This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-20, CWE-20
Bug IDs: CSCwq5
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
blogs_hackernews·2026-04-06
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
This week had real hits. The key software got tampered with. Active bugs showed up in the tools people use every day. Some attacks didn’t even need much effort because the path was already there.
One weak spot now spreads wider than before. What starts small can reach a lot of systems fast. New bugs, faster use, less time to react.
That’s this week. Read through it.
## ⚡ Threat of the Week
Axios npm Package Compromised by N. Korean Hackers —Threat actors with ties to North Korea seized control of the npm account belonging to the lead m
Checkpoint
6th April – Threat Intelligence Report
blogs_checkpoint·2026-04-06
CVE-2026-20093 6th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 6th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 30th March, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
The European Commission, the European Union’s executive body, has confirmed a data breach after its Europa.eu platform was compromised through a third-party exchange linked to the Trivy supply chain attack. The incident affected at least one Amazon Web Services account and resulted in data theft, while websites and internal sys
Hackernews
Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise
blogs_hackernews·2026-04-02·CVSS 9.8
[CRITICAL] Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise
Cisco has released updates to address a critical security flaw in the Integrated Management Controller (IMC) that, if successfully exploited, could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system with elevated privileges.
The vulnerability, tracked as CVE-2026-20093, carries a CVSS score of 9.8 out of a maximum of 10.0.
"This vulnerability is due to incorrect handling of password change requests," Cisco said in an advisory released Wednesday. "An attacker could exploit this vulnerability by sending a c
Bleepingcomputer
Critical Cisco IMC auth bypass gives attackers Admin access
blogs_bleepingcomputer·2026-04-02·CVSS 9.8
[CRITICAL] Critical Cisco IMC auth bypass gives attackers Admin access
## Critical Cisco IMC auth bypass gives attackers Admin access
## Sergiu Gatlan
Cisco has released security updates to address several critical and high-severity vulnerabilities, including an Integrated Management Controller (IMC) authentication bypass that allows attackers to gain Admin access.
Also known as CIMC, Cisco IMC is a hardware module embedded on the motherboard of Cisco servers that provides out-of-band management (even if the operating system is powered off or crashed) for UCS C-Series and E-Series servers via multiple interfaces, including XML API, web (WebUI), and command-line (CLI).
Tracked as CVE-2026-20093 , the vulnerability was found in the Cisco IMC password change functionality and can be remotely exploited by unauthenticated attackers to bypass authentication and
2026-04-01
Published