What is CVE-2026-20288?
A vulnerability in the web-based management interface of Cisco IMC allows an authenticated remote attacker with admin privileges to execute arbitrary commands on the underlying OS and escalate to root. Affected systems should be patched immediately and admin access strictly controlled.
Azərbaycanca: Cisco IMC veb idarəetmə interfeysində autentifikasiya olunmuş, admin hüquqlarına malik uzaqdan hücumçuya əməliyyat sistemində əmr icra etməyə və root səviyyəsinə yüksəlməyə imkan verən boşluqdur. Təsirə məruz qalmış sistemlərdə təcili yamaq tətbiq edilməli, admin girişləri ciddi məhdudlaşdırılmalıdır.
Related CVEs
link basis: shared vendor: Cisco
FAQ2
What level of access does an attacker need to exploit CVE-2026-20288?
The attacker must be an authenticated remote user with admin privileges on the Cisco IMC web-based management interface.
What can an attacker achieve by successfully exploiting this vulnerability?
The attacker can execute arbitrary commands on the underlying OS and escalate privileges to root.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.