Cross-Site Scripting Vulnerability in Cisco Integrated Management Controller
CVE-2026-20198

4.8MEDIUM

What is CVE-2026-20198?

A vulnerability exists in the web-based management interface of Cisco Integrated Management Controller (IMC) that may allow an authenticated, remote attacker to execute a cross-site scripting (XSS) attack. This issue stems from inadequate validation of user input, enabling attackers to craft malicious links that, when clicked by a user, can lead to the execution of arbitrary script code in the user's browser. Such an exploit could facilitate access to sensitive information available in the user's browser session.

Affected Version(s)

Cisco Enterprise NFV Infrastructure Software 4.1.1

Cisco Enterprise NFV Infrastructure Software 3.9.1

Cisco Enterprise NFV Infrastructure Software 3.5.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.