SB2026040172 - Multiple vulnerabilities in Cisco Unified Computing System (UCS)
Published: April 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 secuirty vulnerabilities.
1) OS command injection (CVE-ID: CVE-2026-20095)
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the web-based management interface of Cisco IMC. A remote privileged user can pass specially crafted data to the application and execute arbitrary OS commands as root on the target system.
2) OS Command Injection (CVE-ID: CVE-2026-20096)
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the web-based management interface of Cisco IMC. A remote privileged user can pass specially crafted data to the application and execute arbitrary OS commands as root on the target system.
3) OS command injection (CVE-ID: CVE-2026-20094)
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the web-based management interface of Cisco IMC. A remote user with read-only privileges can pass specially crafted data to the application and execute arbitrary OS commands as root on the target system.
4) Out-of-bounds write (CVE-ID: CVE-2026-20097)
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to a boundary error the web-based management interface of Cisco IMC. A remote attacker can send a specially crafted HTTP request to the web interface, trigger an out-of-bounds write and execute arbitrary code as root.
Remediation
Install update from vendor's website.
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-3hKN3bVt
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwr60889
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws00368
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws00370
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwr60894
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws00376
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws00378
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwr60021
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws00363
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwr60925