Cross-Site Scripting Vulnerability in Cisco IMC Web Management Interface
CVE-2026-20087

4.8MEDIUM

What is CVE-2026-20087?

A stored Cross-Site Scripting (XSS) vulnerability exists in the web-based management interface of Cisco IMC, arising from inadequate validation of user inputs. An authenticated attacker with administrative privileges could exploit this weakness by luring a user into clicking on a specially crafted link. Upon successful execution, this attack could allow the attacker to run arbitrary script code in the victim's browser or gain access to sensitive browser-protected information, thereby posing significant security risks.

Affected Version(s)

Cisco Enterprise NFV Infrastructure Software 4.1.1

Cisco Enterprise NFV Infrastructure Software 3.9.1

Cisco Enterprise NFV Infrastructure Software 3.5.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.