• PoC PUBLIC

CVE-2026-20200: authenticated remote code execution in Cisco Cisco Unified Computing System (Standalone)

An authenticated, remote attacker with low privileges can run arbitrary commands and escalate to root on Cisco Unified Computing System (Standalone) web management interfaces; this is tracked as CVE-2026-20200. The flaw affects multiple 4.x branch builds (examples include 4.3(1.230097), 4.3(2.240002) and several 4.3.x builds listed by the vendor). Exploitation requires network access to the product's web-based management interface and a low-privilege account that can submit crafted inputs to the interface.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
8.8HIGH
EPSS
0.00734
CWE
CWE-141
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Act urgently: public exploit code exists for this flaw, so immediately restrict network access to the web management interface and follow vendor guidance to mitigate exposure.

What is CVE-2026-20200?

An authenticated, remote attacker with low privileges can run arbitrary commands and escalate to root on Cisco Unified Computing System (Standalone) web management interfaces; this is tracked as CVE-2026-20200. The flaw affects multiple 4.x branch builds (examples include 4.3(1.230097), 4.3(2.240002) and several 4.3.x builds listed by the vendor). Exploitation requires network access to the product's web-based management interface and a low-privilege account that can submit crafted inputs to the interface.

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Cisco Cisco Unified Computing System (Standalone) are affected?

BRANCHAFFECTEDFIXED
4.x4.3(1.230097)
4.x4.3(1.230124)
4.x4.3(1.230138)
4.x4.3(2.230207)
4.x4.3(2.230270)
4.x4.3(2.240002)
4.x4.3(3.240022)
4.x4.3(3.240043)
4.x4.3(4.240142)
4.x4.3(4.240152)

Is CVE-2026-20200 being exploited?

Public exploit code is available.

How to fix CVE-2026-20200

  1. Restrict access to the web-based management interface to trusted management networks and use IP allowlists.
  2. Increase authentication controls for the management interface and rotate administrative credentials.
  3. Monitor management interface logs and host integrity for suspicious commands or privilege escalation indicators.
  4. Follow Cisco's official advisory and apply vendor guidance as it becomes available.

Frequently asked questions

Is CVE-2026-20200 being actively exploited?

Public exploit code is available for CVE-2026-20200; the vulnerability is not listed in CISA's KEV catalog as of 2026-09-29.

Which Cisco Unified Computing System (Standalone) versions are affected by CVE-2026-20200?

Multiple 4.x branch builds of Cisco Unified Computing System (Standalone) are affected, including several 4.3(...) builds such as 4.3(1.230097), 4.3(2.240002), and others listed by the vendor.

Is there a patch for CVE-2026-20200?

There are no fixed versions listed for CVE-2026-20200 in the vendor-affected data as of 2026-09-29; follow Cisco guidance for mitigations.

Does CVE-2026-20200 require authentication?

Yes; the issue requires a low-privilege authenticated account interacting with the Cisco Unified Computing System (Standalone) web-based management interface.

References