CVE-2026-20293
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
Description
A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software. This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device.
In plain language
AI Act nowCVE-2026-20293 is a Cisco server/appliance UEFI firmware flaw that lets someone with local console or physical access bypass Secure Boot and run software before your system starts—this is a serious concern if you have any chance of unattended physical access or high-risk console access.
CVE-2026-20293 is a UEFI Shell Secure Boot bypass (CWE-749) on Cisco UCS and UCS-based appliances, where an attacker who can reach the UEFI Shell at boot (via local console/physical access, and sometimes with low-privilege credentials) can modify Secure Boot-related settings to execute unauthorized pre-boot software.
What to do now
- Confirm whether your environment uses one of these products: cisco enterprise nfv infrastructure software, cisco unified computing system (managed), cisco unified computing system (standalone), cisco unified computing system e-series software (ucse).
- Check whether UEFI Secure Boot is enabled on the affected servers/appliances (the bypass is possible when Secure Boot is enabled).
- Assess whether anyone outside trusted staff can reach the local console/boot menu or obtain physical control of the device (the attack requires local/physical access to select the UEFI Shell boot option).
- If you have any realistic risk of local/physical access, immediately tighten access controls: restrict console access, add physical security, and prevent booting into the UEFI Shell wherever your management interface/firmware policy allows.
- Contact Cisco support or your vendor/managed service provider to obtain the official guidance and confirm whether a firmware update exists for CVE-2026-20293; no fix information is available from the provided findings.
- If a fix is not yet available, prioritize compensating controls (strong physical security, strict console/boot policy, and tighter administrative access) and document a risk acceptance decision until a patch is released.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20293 and every CVE in our database. Create a free account — no credit card required.
Create Free Account