CVE-2026-20200Cisco · Unified_computing_system
Vulnerability data via NVD (ingested)
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-20200product:"Cisco Unified Computing System" version:"4.3\(1.230097\)"http.html:"Unified Computing System"More intel sources (5)
vuln:CVE-2026-20200vulnerabilities.cve_id: CVE-2026-20200CVE-2026-20200CVE-2026-20200"CVE-2026-20200" exploit -site:nvd.nist.gov