#VU124792 Missing authorization in Cisco Unified Computing System (UCS) - CVE-2026-20093
Published: April 1, 2026
Cisco Unified Computing System (UCS)
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authorization checks within the password change functionality of Cisco IMC. A remote non-authenticated attacker can send a specially crafted HTTP request and change password for arbitrary accounts on the system, including administrative accounts.