/00 — boot sequence

Hello.

Article

CVE-2026-20200 Cisco IMC Argument Injection Root RCE

August 9, 2026•7 min read
cisco imc cve-2026-20200 rce argument-injection

What happened

Cisco published an advisory for two argument injection flaws in the Cisco Integrated Management Controller (IMC) on August 6, 2026. The serious one, CVE-2026-20200, lets an authenticated remote attacker with low privileges run arbitrary commands on the underlying operating system and elevate to root.

This bug, the Cisco IMC argument injection, sits inside the web based management interface. The IMC web app has a handy feature: you can add an SSH public key by pasting it, uploading it, or fetching it from another server over HTTP or FTP. That last option is where the trouble starts. The backend builds a script call from the parameters you supply, and the script feeds those parameters straight into curl. The arguments are not fully filtered, so an attacker can inject extra curl flags into the call, control what the command does, and from there read or write files and execute commands. Because the script and curl run as root, this becomes a full takeover of the management controller.

The finding came out of a commissioned security assessment by Christoph Peil at NSIDE ATTACK LOGIC, who reported it to Cisco in February 2026. The advisory, cisco-sa-cimc-arg-inject-upSHdMfU, shipped with fixed firmware, and NSIDE published a proof of concept toolkit named CIMCown on GitHub the same day.

Vulnerability details

FieldValue
CVE IDCVE-2026-20200
Bug typeArgument injection (CWE-141)
LocationIMC web interface, SSH key import
Access neededAuthenticated remote account, low privileges
CVSS 3.1 base8.8 High (Cisco), 9.8 per NSIDE
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ResultRoot on the IMC operating system
PoC statusPublic (CIMCown)

A second flaw, CVE-2026-20288, sits in the same web interface and same code path but requires an Admin account on the IMC. Cisco rates it 6.5. Both are patched in the same firmware releases.

How the attack works

The vulnerable screen is the SSH key import form. When you tell the IMC to pull a key from a remote host, the backend runs a script with the host and path as arguments:

/etc/scripts/download_ssh_keys.sh http 123.123.123.123 /tmp/remote-key.pub

The script builds a curl command from these arguments to fetch the file. Because the parameters are not filtered thoroughly, an attacker can smuggle extra curl flags into the call. curl is more capable than a download client. With the right flags it can read local files, write files anywhere on the system, and with library loading it can run commands. The script runs as root, so the injected curl also runs as root.

NSIDE's CIMCown proof of concept treats this as a remote shell box: it can list and download files, upload payloads, and generate a Go reverse shell binary that lands as root on the IMC. The whole flow needs an authenticated web session, but any working account is enough, even a read only user.

Which systems are affected

According to the Cisco advisory tables, the platform with CVE-2026-20200 and the fixed release are:

ProductFirst fixed release
UCS C-Series M7 and M8 rack server4.3(6.260033) or 6.0(2.260044)

The wider list includes UCS C-Series M5 and M6, UCS E-Series, UCS S-Series storage servers, 5000 Series ENCS, and Catalyst 8300 edge uCPE. These exposures are mostly the second CVE, and the fix varies by branch: the M5 families use 4.2(3r) or 4.3(2.260020), the M6 use 4.3(6.260054) or 6.0(2.260143), the E-Series M6 use 4.15.4, and the ENCS and uCPE upgrades roll out through NFVIS 4.12.8, 4.15.6, 4.18.5 or 26.1.2.

A large set of Cisco appliances also embeds these platforms, from Secure Firewall Management Center to Secure Endpoint Private Cloud and the Secure Network Server (ISE SNS) boxes. Exact versions live in the Fixed Releases section of the advisory; running a pre-fixed build counts as vulnerable.

Impact assessment

The Cisco management controller is the counterpart of the Dell iDRAC or the HPE iLO. It handles power control, BIOS updates, SecureBoot configuration, virtual media, and console access for the server. Root on the IMC sits below the operating system. An attacker with that access can change firmware, mount a boot image through virtual media, kill recovery paths, and hide in a place endpoint agents never reach.

For a data center operator this is the bug that stops a maintenance window cold. The exploit does not need much: one valid web account with low privileges, and the web UI reachable over the network. Management networks are often segmented but rarely strict, and this flaw makes every IMC console a standing target.

Mitigation and patching

Cisco states the fix is an upgrade; there is no workaround that closes the hole. The recommendation order:

  1. Find every IMC. Include servers in racks, and every appliance that embeds a UCS C-Series inside, like the Secure Firewall, Secure Endpoint, and SNS boxes. Run a version scan if you can.
  2. Compare the running firmware against the fixed releases list in the advisory. Any build older than the fixed column is vulnerable.
  3. Upgrade UCS C-Series M7/M8 to 4.3(6.260033) or 6.0(2.260044) for CVE-2026-20200. The other platforms follow the per model tables in the advisory. On 5000 ENCS and Catalyst 8300, upgrade via NFVIS bundle (4.12.8, 4.15.6, 4.18.5 or 26.1.2).
  4. Restrict the management plane. The IMC console and SSH access should only be open to the admin network, never to the flat office LAN or the internet.
  5. If you cannot patch in time, NSIDE suggests disabling the web interface entirely, which cuts the entry path for this flaw.

For any known or suspected compromise, treat the controller as hostile afterward: rebuild the device config, rotate its credentials, and reinstall the host OS from a trusted source because the IMC can hold a bootkit.

Detection

The pragmatic early warning sign is a session on the IMC web UI that triggers the SSH key import from a remote shell. Roughly:

  • Audit the IMC logs for key import actions, especially imports from hosts outside your admin subnet
  • Look for reverse shell payloads or unusual files under /tmp on the unit
  • Watch outbound traffic from management networks, a controller does not fetch from random internet hosts

There is no known detection rule from Cisco yet, so the highest value control is a version inventory. If your IMC is above the fixed line you are clean; anything below it must be assumed exposed, especially with a public tool in circulation.

Frequently Asked Questions

Is CVE-2026-20200 limited to low privileges?

Yes. An authenticated account with low privileges is enough, which is what makes this bug so practical. Admin rights are not required.

Is there a public exploit?

Yes. NSIDE released a formal advisory and the same team published proof of concept tooling on GitHub together with the Cisco advisory.

Which CVEs are fixed together?

CVE-2026-20200 and CVE-2026-20288 are fixed in the same firmware releases. Both are argument injection flaws in the IMC web interface.

Is the IMC the same as iDRAC?

It is Cisco's counterpart. It provides out of band management for firmware, BIOS, power, and console on UCS rack servers.

Does a unified management stack remove the risk?

A UCS system that is under UCS Manager or Intersight still runs IMC code underneath, so firmware updates stay in the runbook even when the standalone console is not the point of entry.

Key takeaways

  • CVE-2026-20200 is a root level argument injection in the Cisco IMC web UI, reachable with low privilege credentials
  • The attack uses the SSH key import to inject curl arguments and execute code as root on the controller
  • A public PoC was published the same day as the advisory on August 6, 2026
  • UCS C-Series M7/M8 need 4.3(6.260033) or 6.0(2.260044); the other platforms follow the per model tables
  • Segment the management network, restrict IMC access to admin hosts, and treat the console as a trusted device, because a patch gap is a risk

Sources:

  • Cisco Security Advisory: Cisco Integrated Management Controller Interface Argument Injection (cisco-sa-cimc-arg-inject-uppf), August 6, 2026
  • NSIDE ATTACK LOGIC advisory NSIDE-SA-2026-003 and blog writeup by Christoph Peil
  • NVD records: CVE-2026-20200 and CVE-2026-20288
  • CIMCown proof of concept repository on GitHub

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.