Cisco Fixes Critical IMC Bug, Allows Root Access
Cisco has patched a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s web interface. The fix was part of Cisco's August 5 advisory batch, and unlike other bugs squashed by hardening releases for IOS XE and SD-WAN, this one has a public proof-of-concept exploit.
The vulnerability affects the web-based management interface of Cisco IMC, due to improper validation of user-supplied input. An attacker with low privileges could exploit this vulnerability by entering crafted inputs, allowing them to execute arbitrary commands on the underlying operating system as the root user. The researcher who discovered the flaw has published a proof-of-concept exploit dubbed CIMCown on GitHub.
Cisco recommends updating vulnerable products, UCS C-Series M7 and M8 Rack Servers in standalone mode, and disabling the web interface if an update is not possible at short notice. The company emphasizes that such interfaces should never be exposed openly to internal or public networks, with a strictly segmented management network, restrictive access controls, and clean rights-and-roles concept significantly reducing the attack surface.