CVE-2026-20288 is a medium-severity vulnerability in the Cisco Integrated Management Controller (IMC) with a CVSS score of 6.5. It allows an authenticated remote attacker with Admin privileges to execute arbitrary commands and elevate to root. Cisco has released fixes.