Description
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS attack against a user of the web-based management interface of an affected device.

These vulnerabilities are due to insufficient sanitization of user-supplied data that is stored in the web page. An attacker could exploit these vulnerabilities by convincing a user of the interface to click a specific link or view an affected web page. The injected script code may be executed in the context of the web-based management interface or allow the attacker to access sensitive browser-based information.
Published: 2026-04-15
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an authenticated, remote attacker who has administrative write privileges on Cisco Identity Services Engine to inject malicious script payloads into the web‑based management interface. Stored or reflected cross‑site scripting could execute in the victim’s browser context, giving the attacker the ability to run arbitrary code, read sensitive data stored in the browser, or hijack the user session. The impact on confidentiality, integrity, or availability is limited to the user interacting with the compromised web page and does not provide full system compromise.

Affected Systems

Cisco Identity Services Engine Software. Version information is not specified in the advisory.

Risk and Exploitability

With a CVSS score of 4.8 the vulnerability is considered moderate. No EPSS score is available and the issue is not listed in the CISA KEV catalog. Exploitation requires an authenticated admin user and relies on a victim clicking a malicious link or visiting an affected page, making the attack vector indirect but still feasible for attackers with the necessary access. The overall risk is moderate for environments where administrative credentials are shared or where users have write access to the management interface.

Generated by OpenCVE AI on April 15, 2026 at 22:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Cisco Identity Services Engine patch or upgrade published in the official Cisco advisory.
  • Restrict administrative write access and ensure only trusted personnel can manage the web‑based interface.
  • Disable unused web‑based management features or harden the web server configuration to reduce the attack surface.

Generated by OpenCVE AI on April 15, 2026 at 22:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Apr 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Software

Wed, 15 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
Description Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative&nbsp;write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS attack against a user of the web-based management interface of an affected device. These vulnerabilities are due to insufficient sanitization of user-supplied data that is stored in the web page. An attacker could exploit these vulnerabilities by convincing a user of the interface to click a specific link or view an affected web page. The injected script code may be executed in the context of the web-based management interface or allow the attacker to access sensitive browser-based information.
Title Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Cisco Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-04-15T17:06:38.222Z

Reserved: 2025-10-08T11:59:15.380Z

Link: CVE-2026-20132

cve-icon Vulnrichment

Updated: 2026-04-15T16:56:38.817Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-15T17:17:01.967

Modified: 2026-04-17T15:09:46.880

Link: CVE-2026-20132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T22:30:16Z

Weaknesses