Description
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.

This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.
Published: 2026-08-05
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) allows an authenticated, remote attacker to conduct a cross‑site scripting attack against a user of the interface. The flaw results from insufficient validation of user input, enabling the attacker to deceptively persuade a legitimate user to click a crafted link. When the victim’s browser renders the crafted content, the attacker can execute arbitrary script code or exfiltrate sensitive browser‑based information, potentially compromising the victim’s session or leading to further attacks.

Affected Systems

The vulnerability affects Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), and Cisco Unified Computing System E‑Series Software (UCSE). Version details were not disclosed in the advisory, so any installation of the listed products without an available update is potentially vulnerable.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate impact. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker be authenticated to the IMC web interface but only needs to convince an end‑user to interact with a maliciously crafted link. The attack vector is remote, user‑side, relying on social engineering rather than an automated payload.

Generated by OpenCVE AI on August 5, 2026 at 18:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑released patch or update for Cisco Integrated Management Controller as soon as it becomes available.
  • Restrict or disable access to the IMC web interface for users who do not require administrative privileges, and enforce strong authentication controls.
  • Implement web‑security measures such as a strong Content Security Policy to mitigate the impact of potential XSS, and ensure that all user‑submitted data is properly escaped or sanitized in the interface.

Generated by OpenCVE AI on August 5, 2026 at 18:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.
Title Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-05T17:20:19.990Z

Reserved: 2025-10-08T11:59:15.397Z

Link: CVE-2026-20198

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T19:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')