Stored XSS Vulnerability in Cisco IMC Web Management Interface
CVE-2026-20090
4.8MEDIUM
What is CVE-2026-20090?
A vulnerability in the web-based management interface of Cisco IMC allows authenticated remote attackers with administrative privileges to execute stored XSS attacks. This flaw arises from inadequate input validation, which can be exploited by tricking a user into clicking a specially crafted link. A successful attack can enable the execution of arbitrary scripts in the victim's browser and compromise sensitive, browser-based information.
Affected Version(s)
Cisco Enterprise NFV Infrastructure Software 4.1.1
Cisco Enterprise NFV Infrastructure Software 3.9.1
Cisco Enterprise NFV Infrastructure Software 3.5.2