Stored XSS Vulnerability in Cisco IMC Management Interface
CVE-2026-20088
4.8MEDIUM
What is CVE-2026-20088?
A vulnerability exists in the web-based management interface of Cisco IMC that allows an authenticated attacker, with administrative privileges, to conduct a stored XSS attack. This flaw arises from inadequate validation of user inputs, potentially enabling an attacker to persuade users to click on a malicious link. If successfully exploited, this can lead to the execution of arbitrary script code in the browser of the targeted user or access to sensitive browser-based data.
Affected Version(s)
Cisco Enterprise NFV Infrastructure Software 4.1.1
Cisco Enterprise NFV Infrastructure Software 3.9.1
Cisco Enterprise NFV Infrastructure Software 3.5.2