Stored XSS Vulnerability in Cisco IMC Management Interface
CVE-2026-20088

4.8MEDIUM

What is CVE-2026-20088?

A vulnerability exists in the web-based management interface of Cisco IMC that allows an authenticated attacker, with administrative privileges, to conduct a stored XSS attack. This flaw arises from inadequate validation of user inputs, potentially enabling an attacker to persuade users to click on a malicious link. If successfully exploited, this can lead to the execution of arbitrary script code in the browser of the targeted user or access to sensitive browser-based data.

Affected Version(s)

Cisco Enterprise NFV Infrastructure Software 4.1.1

Cisco Enterprise NFV Infrastructure Software 3.9.1

Cisco Enterprise NFV Infrastructure Software 3.5.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.