Cisco IMC Command Injection Lets Read-Only Users Execute as Root
Cisco Integrated Management Controller (IMC) has three separate command injection vulnerabilities (CVE-2026-20094, CVE-2026-20095, CVE-2026-20096) in its web-based management interface. These flaws allow authenticated attackers, including those with only read-only access, to execute arbitrary commands as the root user on the underlying operating system.
This elevates the risk because limiting user roles does not prevent full system compromise. There are no workarounds; only Cisco's software updates fix the issue. Organizations with IMC exposed to administrative networks or third-party access face heightened risk and must prioritize patching immediately.