CVE-2026-20200 is a high-severity vulnerability in the Cisco Integrated Management Controller (IMC) with a CVSS score of 8.8. It allows an authenticated remote attacker with low privileges to execute arbitrary commands and elevate to root. A proof-of-concept exploit is available. Cisco has released fixes.