Stored XSS Vulnerability in Cisco IMC Web Management Interface
CVE-2026-20090

4.8MEDIUM

What is CVE-2026-20090?

A vulnerability in the web-based management interface of Cisco IMC allows authenticated remote attackers with administrative privileges to execute stored XSS attacks. This flaw arises from inadequate input validation, which can be exploited by tricking a user into clicking a specially crafted link. A successful attack can enable the execution of arbitrary scripts in the victim's browser and compromise sensitive, browser-based information.

Affected Version(s)

Cisco Enterprise NFV Infrastructure Software 4.1.1

Cisco Enterprise NFV Infrastructure Software 3.9.1

Cisco Enterprise NFV Infrastructure Software 3.5.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.