Cisco Unified Computing System (Standalone): remote code execution
High8.8CVE-2026-20200 · Published Aug 5, 2026 · updated Aug 31, 2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cisco Unified Computing System (Standalone) Product | <= 4.3(1.230097) | No fix yet |
| <= 4.3(1.230124) | No fix yet | |
| <= 4.3(1.230138) | No fix yet | |
| <= 4.3(2.230207) | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-141
More Cisco advisories
All Cisco| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 5 | Cisco Catalyst SD-WAN: cleartext secrets | High8.8 | No fix yet |
| Aug 5 | Cisco Catalyst SD-WAN: improper quantity validation | High7.7 | No fix yet |
| Aug 5 | Cisco IOS XE Software: denial of service | Medium4.3 | No fix yet |
| Aug 5 | Cisco Catalyst SD-WAN: link following | Critical9.1 | No fix yet |
| Aug 5 | Cisco IOS XE Software: denial of service | Medium6.3 | No fix yet |
| Aug 5 | Cisco IOS XE Software: denial of service | High8.6 | No fix yet |