CVE-2026-20093: Cisco IMC Authentication Bypass — Unauthenticated Admin Access via Password Change Manipulation — Threadlinqs Intelligence
As of 2026-05-30, CVE-2026-20093: Cisco IMC Authentication Bypass — Unauthenticated Admin Access via Password Change Manipulation is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0316 · Severity: CRITICAL · CVSS: 9.8 · Status: PATCHED · Category: VULNERABILITY
Attribution: N/A · UNKNOWN
Critical authentication bypass vulnerability (CVSS 9.8) in Cisco Integrated Management Controller (IMC) allows unauthenticated remote attackers to bypass authentication and gain full administrative
CVE-2026-20093 is a critical authentication bypass vulnerability in the Cisco Integrated Management Controller (IMC), the out-of-band management service used across Cisco UCS server platforms. The flaw resides in the password change functionality of the IMC web interface and XML API.
The root cause is improper input validation (CWE-20) in how IMC processes password modification requests. The system fails to validate the authorization context during password modification requests before processing backend database updates. An unauthenticated attacker can craft an XML POST request targeting the configConfMo method with the aaaUser object class, manipulating the default admin account Distinguished Name (DN) at sys/user-ext/user-admin. This allows direct credential manipulation without a valid authenticated session.
The attack is network-based with low complexity, requiring no privileges or user interaction. A successful exploit allows the attacker to bypass all authentication mechanisms, alter passwords of any user including the Admin account, and gain full administrative access to the affected system. Through the IMC management interface (accessible via XML API, WebUI, and CLI), an attacker with admin access can control server hardware, modify BIOS settings, access virtual media, monitor hardware health, and potentially pivot to managed workloads.
The vulnerability affects multiple Cisco product families running vulnerable IMC firmware: UCS C-Series M5 and M6 Rack Servers in standalone mode, UCS E-Series M3 and M6 servers, 5000 Series Enterprise Network Compute Systems (ENCS), and Catalyst 8300 Series Edge uCPE. Dependent appliances that embed Cisco IMC are also affected, including APIC Servers, Cyber Vision Center Appliances, Secure Firewall Management Center appliances, and Malware Analytics Appliances.
Notably, UCS B-Series Blade Servers, UCS C-Series M7/M8 Rack Servers, servers managed via Fabric Interconnects in UCS Manager or Intersight Managed Mode, UCS S-Series Storage Servers, and UCS X-Series Modular Systems are NOT affected.
No workarounds exist for this vulnerability. Cisco has released fixed firmware versions and strongly recommends immediate patching. As interim mitigation, organizations should restrict IMC management interface access to trusted networks only, implement network segmentation, and enforce VPN-only or zero-trust access controls for out-of-band management.
The vulnerability was discovered by security researcher 'jyh' and disclosed by Cisco PSIRT on April 1, 2026 as part of a batch that also included CVE-2026-20160, a separate CVSS 9.8 RCE in Cisco Smart Software Manager On-Prem. Cisco PSIRT reports no evidence of active exploitation in the wild as of the disclosure date, though the low complexity and high impact make exploitation highly likely once PoC code circulates.
Target sectors: technology, government, financial, healthcare, telecommunications, education, manufacturing, defense, energy, critical-infrastructure
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-20093, T1190, T1556, T1098, T1078, T1078, T1021, T1203, T1082, T1531, T1602