Cisco Enterprise NFV Infrastructure Software: remote code execution
Medium6.5CVE-2026-20288 · Published Aug 5, 2026 · updated Sep 16, 2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cisco Enterprise NFV Infrastructure Software Product | <= 4.1.1 | No fix yet |
| <= 3.9.1 | No fix yet | |
| <= 3.5.2 | No fix yet | |
| <= 3.12.2 | No fix yet | |
| Cisco Unified Computing System (Standalone) Product | <= 4.0(2g) | No fix yet |
| <= 3.1(2i) | No fix yet | |
| <= 3.1(1d) | No fix yet | |
| <= 4.0(4i) | No fix yet | |
| Cisco Unified Computing System E-Series Software (UCSE) Product | <= 3.2.7 | No fix yet |
| <= 3.2.6 | No fix yet | |
| <= 3.2.4 | No fix yet | |
| <= 3.2.10 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-146
More Cisco advisories
All Cisco| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 5 | Cisco Catalyst SD-WAN: cleartext secrets | High8.8 | No fix yet |
| Aug 5 | Cisco Catalyst SD-WAN: improper quantity validation | High7.7 | No fix yet |
| Aug 5 | Cisco IOS XE Software: denial of service | Medium4.3 | No fix yet |
| Aug 5 | Cisco Catalyst SD-WAN: link following | Critical9.1 | No fix yet |
| Aug 5 | Cisco IOS XE Software: denial of service | Medium6.3 | No fix yet |
| Aug 5 | Cisco IOS XE Software: denial of service | High8.6 | No fix yet |