Platform
cisco
Component
cisco-integrated-management-controller
Fixed in
4.1.2
3.9.2
3.5.3
3.12.3
3.6.3
3.9.3
3.11.4
3.11.2
3.5.2
3.3.2
3.10.3
3.12.2
3.4.2
3.12.2
3.6.4
3.8.2
3.11.3
3.12.2
3.12.4
3.10.2
3.6.2
3.10.4
3.7.2
4.1.3
4.2.2
4.2.3
4.4.2
4.4.3
4.5.2
4.4.4
4.6.2
4.7.2
4.6.3
4.6.3
4.6.3
4.8.2
4.8.3
4.9.2
4.6.4
4.9.3
4.9.3
4.10.2
4.9.4
4.11.2
4.9.5
4.12.2
4.6.5
4.12.3
4.13.2
4.9.5
4.9.6
4.12.4
4.6.6
4.9.5
4.14.2
4.6.4
4.9.5
4.12.5
4.15.2
4.9.7
4.16.2
4.15.3
4.12.6
4.15.4
4.15.5
4.18.2
4.12.7
4.18.3
4.18.3
4.0.1
3.1.1
3.1.1
4.0.1
4.1.1
4.0.1
4.0.1
4.0.1
4.0.1
4.0.1
4.0.1
3.1.1
4.0.1
4.0.1
4.0.1
4.0.1
3.1.1
4.0.1
4.1.1
3.1.1
4.0.1
3.1.1
3.1.1
3.1.1
4.0.1
4.1.1
4.0.1
4.0.1
4.0.1
3.1.1
3.1.1
3.1.1
4.0.1
3.1.1
4.0.1
4.0.1
3.1.1
4.0.1
3.1.1
4.0.1
3.1.1
4.0.1
4.1.1
4.1.1
4.0.1
4.1.1
3.1.1
4.1.1
4.0.1
4.0.1
4.1.1
4.1.1
4.0.1
4.1.1
4.1.1
4.0.1
4.0.1
4.1.1
4.0.1
4.1.1
4.1.1
4.1.1
4.1.1
4.1.1
4.1.1
4.1.1
4.2.1
4.1.1
4.2.1
4.2.1
4.2.1
4.1.1
4.2.1
4.3.1
4.2.1
4.2.1
4.2.1
4.2.1
4.2.1
4.2.1
4.2.1
4.2.1
4.3.1
4.1.1
4.2.1
4.3.1
4.2.1
4.3.1
4.2.1
4.2.1
4.3.1
4.1.1
4.1.1
4.3.1
4.3.1
4.2.1
4.1.1
4.3.1
4.3.1
4.3.1
4.3.1
4.3.1
4.3.1
4.2.1
4.3.1
4.3.1
4.3.1
4.3.1
4.2.1
4.3.1
4.3.1
4.3.1
4.3.1
4.2.1
4.3.1
4.2.1
4.3.1
4.3.1
4.3.1
4.3.1
4.3.1
4.3.1
4.3.1
4.3.1
4.3.1
4.3.1
4.3.1
4.3.1
6.0.1
4.2.1
6.0.1
4.3.1
4.3.1
4.3.1
4.3.1
4.3.1
4.3.1
6.0.1
4.3.1
4.3.1
4.3.1
3.2.8
3.2.7
3.2.5
3.2.11
3.2.3
3.2.4
2.4.1
3.2.2
3.2.12
3.2.9
3.1.2
3.0.3
2.1.1
2.2.3
3.1.3
3.0.2
2.3.3
2.3.6
2.2.2
3.1.5
2.4.2
2.3.2
3.1.4
2.3.4
2.4.3
3.1.6
3.1.1
2.0.1
3.2.12
3.2.12
3.2.13
3.2.14
3.2.15
4.11.2
3.2.16
4.12.2
3.2.16
4.12.3
3.2.17
4.15.3
CVE-2026-20093 is a critical authentication bypass vulnerability affecting Cisco Integrated Management Controller (IMC) versions up to 6.0(1.250131). This flaw allows an unauthenticated, remote attacker to bypass authentication and gain full administrative access to the system. Successful exploitation could lead to complete system compromise and data exfiltration. A patch is available from Cisco to address this vulnerability.
The impact of CVE-2026-20093 is severe. An attacker exploiting this vulnerability can bypass authentication entirely, effectively gaining root-level access to the IMC system. This allows them to modify system configurations, access sensitive data, and potentially pivot to other systems on the network. The ability to alter user passwords, including the Admin account, grants persistent and unrestricted control. This vulnerability shares similarities with other authentication bypass flaws where improper input validation leads to unauthorized access, potentially allowing for widespread disruption and data theft.
CVE-2026-20093 was publicly disclosed on April 1, 2026. Its CVSS score of 9.8 (CRITICAL) reflects the ease of exploitation and the potential for significant impact. Public proof-of-concept exploits are likely to emerge given the vulnerability's nature and severity. It is not currently listed on CISA KEV, but its criticality warrants close monitoring. Active exploitation is possible, especially given the lack of immediate patching in many environments.
Exploit Status
EPSS
0.03% (8% percentile)
CISA SSVC
CVSS Vector
The primary mitigation for CVE-2026-20093 is to upgrade to a patched version of Cisco IMC. Cisco has released a fix, and applying it is the most effective way to eliminate the vulnerability. If immediate patching is not possible, consider implementing strict network segmentation to limit the IMC's exposure. While a WAF might offer limited protection, it's unlikely to be effective against this authentication bypass. Closely monitor IMC logs for suspicious activity, particularly failed login attempts and unusual configuration changes. After upgrade, confirm by attempting to access the IMC without authentication and verifying that access is denied.
Update the Cisco Integrated Management Controller to an unaffected version. See the Cisco advisory for more details and specific upgrade instructions.
Vulnerability analysis and critical alerts directly to your inbox.
CVE-2026-20093 is a critical vulnerability in Cisco Integrated Management Controller (IMC) allowing unauthenticated attackers to bypass authentication and gain Admin access.
You are affected if your Cisco IMC version is equal to or less than 6.0(1.250131). Check your version immediately.
Upgrade to a patched version of Cisco IMC as soon as possible. Refer to the Cisco advisory for specific fixed versions.
While not confirmed, the vulnerability's severity and ease of exploitation make active exploitation highly probable. Monitor your systems closely.
Refer to the official Cisco Security Advisory for CVE-2026-20093 on the Cisco website (search for the CVE ID).
Upload your dependency file and we'll tell you instantly if this and other CVEs hit you.