SB2026040172 - Multiple vulnerabilities in Cisco Unified Computing System (UCS)
Published: April 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 vulnerabilities.
1) OS command injection (CVE-ID: CVE-2026-20095)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the web-based management interface of Cisco IMC. A remote privileged user can pass specially crafted data to the application and execute arbitrary OS commands as root on the target system.
2) OS Command Injection (CVE-ID: CVE-2026-20096)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the web-based management interface of Cisco IMC. A remote privileged user can pass specially crafted data to the application and execute arbitrary OS commands as root on the target system.
3) OS command injection (CVE-ID: CVE-2026-20094)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the web-based management interface of Cisco IMC. A remote user with read-only privileges can pass specially crafted data to the application and execute arbitrary OS commands as root on the target system.
4) Out-of-bounds write (CVE-ID: CVE-2026-20097)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to a boundary error the web-based management interface of Cisco IMC. A remote attacker can send a specially crafted HTTP request to the web interface, trigger an out-of-bounds write and execute arbitrary code as root.
Remediation
Install update from vendor's website.
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-3hKN3bVt
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwr60889
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws00368
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws00370
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwr60894
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws00376
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws00378
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwr60021
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws00363
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwr60925