Cross-Site Scripting Vulnerability in Cisco IMC Web Management Interface
CVE-2026-20087
4.8MEDIUM
What is CVE-2026-20087?
A stored Cross-Site Scripting (XSS) vulnerability exists in the web-based management interface of Cisco IMC, arising from inadequate validation of user inputs. An authenticated attacker with administrative privileges could exploit this weakness by luring a user into clicking on a specially crafted link. Upon successful execution, this attack could allow the attacker to run arbitrary script code in the victim's browser or gain access to sensitive browser-protected information, thereby posing significant security risks.
Affected Version(s)
Cisco Enterprise NFV Infrastructure Software 4.1.1
Cisco Enterprise NFV Infrastructure Software 3.9.1
Cisco Enterprise NFV Infrastructure Software 3.5.2