Missing authorization in Cisco Unified Computing System (UCS) - CVE-2026-20093
Published: April 1, 2026
Cisco Unified Computing System (UCS)
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authorization checks within the password change functionality of Cisco IMC. A remote non-authenticated attacker can send a specially crafted HTTP request and change password for arbitrary accounts on the system, including administrative accounts.