CVE Tools

CVE-2026-20293

Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

Published: Sep 8, 2026Updated: Sep 11, 2026 Sources: CVE List NVDCWE-749

Description

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software. This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device.

In plain language

AI Act now

CVE-2026-20293 is a Cisco server/appliance UEFI firmware flaw that lets someone with local console or physical access bypass Secure Boot and run software before your system starts—this is a serious concern if you have any chance of unattended physical access or high-risk console access.

Executive summary

CVE-2026-20293 is a UEFI Shell Secure Boot bypass (CWE-749) on Cisco UCS and UCS-based appliances, where an attacker who can reach the UEFI Shell at boot (via local console/physical access, and sometimes with low-privilege credentials) can modify Secure Boot-related settings to execute unauthorized pre-boot software.

If affected, business impact
Full pre-OS compromiseBypass Secure Boot protectionsUnauthorized software executionPotential ransomware staging

What to do now

  1. Confirm whether your environment uses one of these products: cisco enterprise nfv infrastructure software, cisco unified computing system (managed), cisco unified computing system (standalone), cisco unified computing system e-series software (ucse).
  2. Check whether UEFI Secure Boot is enabled on the affected servers/appliances (the bypass is possible when Secure Boot is enabled).
  3. Assess whether anyone outside trusted staff can reach the local console/boot menu or obtain physical control of the device (the attack requires local/physical access to select the UEFI Shell boot option).
  4. If you have any realistic risk of local/physical access, immediately tighten access controls: restrict console access, add physical security, and prevent booting into the UEFI Shell wherever your management interface/firmware policy allows.
  5. Contact Cisco support or your vendor/managed service provider to obtain the official guidance and confirm whether a firmware update exists for CVE-2026-20293; no fix information is available from the provided findings.
  6. If a fix is not yet available, prioritize compensating controls (strong physical security, strict console/boot policy, and tighter administrative access) and document a risk acceptance decision until a patch is released.
May need vendor / contractor work

CVSS Vector Breakdown

AV:LAC:LPR:LUI:NS:UC:HI:HA:N
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:NAvailability
None

Weaknesses

Affected Products

Exploitability

0 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details

References

1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-20293 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows