Description
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface.

This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.
Published: 2026-04-01
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS allowing arbitrary script execution and data theft in the CIMC web UI
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises from insufficient input validation in the web interface of Cisco’s Integrated Management Controller (IMC). An authenticated attacker with administrative privileges can embed malicious script into the UI, which is stored and executed when a user clicks a crafted link. The stored XSS can run arbitrary JavaScript in the victim’s browser, enabling the attacker to exfiltrate credentials, manipulate the interface, or perform additional actions on behalf of the user.

Affected Systems

Affects Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), and Cisco Unified Computing System E-Series Software (UCSE). Exact product versions impacted are not disclosed in the advisory.

Risk and Exploitability

With a CVSS score of 4.8, the vulnerability is of moderate severity. The EPSS score is not available, and it is not listed in CISA’s KEV catalog, indicating no confirmed public exploitation. Exploitation requires an authenticated admin account and the victim’s interaction with a crafted link, but access controls and monitoring can mitigate the risk.

Generated by OpenCVE AI on April 2, 2026 at 02:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Cisco Security advisory for the latest patch or update that addresses the stored XSS vulnerability in the Integrated Management Controller web interface.
  • Apply the vendor’s patch or upgrade to a supported software version that includes the fix.
  • Limit access to the CIMC web UI to authorized administrators and enforce strong authentication mechanisms.
  • Educate users to be cautious of clicking unexpected links in the CIMC UI, and consider blocking scripts from untrusted sources if feasible.
  • Monitor CIMC access logs for signs of script injection or unauthorized activity, and respond promptly.

Generated by OpenCVE AI on April 2, 2026 at 02:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 03 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco enterprise Nfv Infrastructure Software
Cisco unified Computing System
Cisco unified Computing System Software
Vendors & Products Cisco
Cisco enterprise Nfv Infrastructure Software
Cisco unified Computing System
Cisco unified Computing System Software

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.
Title Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Enterprise Nfv Infrastructure Software Unified Computing System Unified Computing System Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-04-22T19:09:56.418Z

Reserved: 2025-10-08T11:59:15.368Z

Link: CVE-2026-20089

cve-icon Vulnrichment

Updated: 2026-04-01T17:44:56.920Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-01T17:28:27.977

Modified: 2026-04-03T16:11:11.357

Link: CVE-2026-20089

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-03T08:58:23Z

Weaknesses