Cisco IMC authentication bypass exposure
Case score 60
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 60
- Main story score
- 60
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
- Vulnerability Cisco IMC/CIMC password-change authentication bypass is the full basis of the case and drives the overall risk. main
Overview
Cisco IMC password change authentication bypass disclosed
Cisco released security updates on 2026-04-02 for Cisco IMC/CIMC after finding CVE-2026-20093 in the password change functionality. An unauthenticated attacker can send a crafted HTTP request to an affected UCS C-Series or E-Series server, bypass authentication, alter user passwords including an Admin account, and gain Admin privileges on the management controller. Cisco said there are no workarounds and strongly recommended upgrading to the fixed software, while PSIRT had not found in-the-wild exploitation or proof-of-concept exploit code.