PT-2026-29557 · Cisco · Cisco Unified Computing System+1

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-20094

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-20094

Affected Products

Cisco Unified Computing System
Cisco Unified Computing System E-Series