A critical authentication bypass vulnerability, CVE-2026-20093, affects Cisco Integrated Management Controller (IMC). According to the NIST/Cisco advisory, the issue is caused by incorrect handling of password change requests in the change-password functionality. An unauthenticated, remote attacker could send a specially crafted HTTP request to an affected IMC device to bypass authentication, alter passwords for any user (including Admin), and gain administrative access. The vulnerability is rated CVSS 3.1 9.8 (CRITICAL) and can result in full confidentiality, integrity, and availability compromise of the affected system.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

