Stored XSS Vulnerability in Cisco IMC Web Management Interface
CVE-2026-20089
4.8MEDIUM
What is CVE-2026-20089?
A security weakness in the web-based management interface of Cisco IMC allows authenticated remote attackers with administrative privileges to launch a stored XSS attack against users. This vulnerability arises from inadequate validation of user input. Attackers can exploit it by tricking users into clicking on a crafted link, leading to the execution of arbitrary scripts in the user's browser and potential access to sensitive browser-based information.
Affected Version(s)
Cisco Enterprise NFV Infrastructure Software 4.1.1
Cisco Enterprise NFV Infrastructure Software 3.9.1
Cisco Enterprise NFV Infrastructure Software 3.5.2