Cross-Site Scripting Vulnerability in Cisco Integrated Management Controller
CVE-2026-20198
4.8MEDIUM
What is CVE-2026-20198?
A vulnerability exists in the web-based management interface of Cisco Integrated Management Controller (IMC) that may allow an authenticated, remote attacker to execute a cross-site scripting (XSS) attack. This issue stems from inadequate validation of user input, enabling attackers to craft malicious links that, when clicked by a user, can lead to the execution of arbitrary script code in the user's browser. Such an exploit could facilitate access to sensitive information available in the user's browser session.
Affected Version(s)
Cisco Enterprise NFV Infrastructure Software 4.1.1
Cisco Enterprise NFV Infrastructure Software 3.9.1
Cisco Enterprise NFV Infrastructure Software 3.5.2