important · Boot chain — Cisco UCS
A low-privilege Cisco account or physical console access can turn an embedded UCS UEFI shell into a Secure Boot bypass.
Affects
Cisco UCS servers and UCS-based compute, security, management, analytics, and network-edge appliances running vulnerable BIOS or firmware releases with UEFI Secure Boot enabled.
A user with KVM credentials, or anyone at the physical console, can enter the embedded shell and use its memory-write commands to overwrite Secure Boot-related values.
Detail and 5 sources
That permits unauthorized pre-OS execution despite Secure Boot.
This remains Secondary because the partial fix was not read for this brief.
Sources
ResearchBombShell: The Signed Backdoor Hiding in Plain Sight on Framework Devices - Eclypsium | Supply Chain Security for the Modern EnterpriseResearchJVNVU#94974158: SPI Flashに組み込まれたUEFI Shellモジュールにおけるセキュアブート回避の脆弱性Code / PoCcvelistV5/cves/2026/20xxx/CVE-2026-20293.json at main · CVEProject/cvelistV5 · GitHubSecondaryCisco UCS UEFI Shell permits Secure Boot variable overwrite (CVE-2026-20293)SecondaryCERT/CC Vulnerability Note VU#718077