PT-2026-29560 · Cisco · Cisco Unified Computing System

Grzegorz Misiun

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-20097

CVSS v3.1

6.5

Medium

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system as the root user.
Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2026-20097

Affected Products

Cisco Unified Computing System