A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges to root.
This vulnerability is due to insufficient input validation of command arguments supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of the affected device with root-level privileges.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Feb 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco
Cisco cisco:adaptive Security Appliance Software Cisco firepower Extensible Operating System Cisco unified Computing System Manager |
|
| Vendors & Products |
Cisco
Cisco cisco:adaptive Security Appliance Software Cisco firepower Extensible Operating System Cisco unified Computing System Manager |
Thu, 26 Feb 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges to root. This vulnerability is due to insufficient input validation of command arguments supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of the affected device with root-level privileges. | |
| Title | Cisco UCS Manager and FXOS Software Command Injection Vulnerability | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisco
Published: 2026-02-25T16:25:38.517Z
Updated: 2026-02-26T14:44:05.716Z
Reserved: 2025-10-08T11:59:15.370Z
Link: CVE-2026-20099
Updated: 2026-02-25T18:17:46.228Z
Status : Awaiting Analysis
Published: 2026-02-25T17:25:27.357
Modified: 2026-02-27T14:06:59.787
Link: CVE-2026-20099
No data.