CVE-2026-20094
published 2026-04-01CVE-2026-20094: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command…
PriorityP268high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.09%
61.8th percentile
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.
Affected
193 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability exists in the web-based management interface of Cisco IMC; monitor for crafted/anomalous commands sent to the IMC web management interface by authenticated users, especially those with read-only privileges attempting privileged operations. ↗
- →Successful exploitation results in command execution as root on the underlying OS; monitor for unexpected root-level process spawning originating from the Cisco IMC web management process. ↗
- →Track Cisco bug IDs CSCwr60021, CSCwr60889, CSCwr60894 for patch and indicator updates from Cisco PSIRT. ↗
- →CWE-77 (Command Injection) and CWE-787 (Out-of-bounds Write) are the weakness types; inspect HTTP requests to the IMC management interface for shell metacharacters or oversized input payloads indicative of injection or buffer manipulation attempts. ↗
- ·Exploitation requires authentication; attacker must hold at least read-only privileges on the Cisco IMC web interface. Unauthenticated access alone is insufficient to trigger this vulnerability. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco3.1
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-757r-g2xf-hjww: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform
ghsa_unreviewed·2026-04-01
CVE-2026-20094 [HIGH] CWE-77 GHSA-757r-g2xf-hjww: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.
Cisco
Cisco Integrated Management Controller Command Injection and Remote Code Execution Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2026-20094 Cisco Integrated Management Controller Command Injection and Remote Code Execution Vulnerabilities
CVE-2026-20094: Cisco Integrated Management Controller Command Injection and Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary code or commands on the underlying operating system of an affected system and elevate privileges to root . For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-77, CWE-787, CWE-77, CWE-787
Bug IDs: CSCwr60021, CSCwr60889, CSCwr60894, CSCwr60021, CSCwr60889
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-01
Published