Stored XSS Vulnerability in Cisco IMC Web Management Interface
CVE-2026-20089

4.8MEDIUM

What is CVE-2026-20089?

A security weakness in the web-based management interface of Cisco IMC allows authenticated remote attackers with administrative privileges to launch a stored XSS attack against users. This vulnerability arises from inadequate validation of user input. Attackers can exploit it by tricking users into clicking on a crafted link, leading to the execution of arbitrary scripts in the user's browser and potential access to sensitive browser-based information.

Affected Version(s)

Cisco Enterprise NFV Infrastructure Software 4.1.1

Cisco Enterprise NFV Infrastructure Software 3.9.1

Cisco Enterprise NFV Infrastructure Software 3.5.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.