Impact
CVE-2026-20309 reveals a reflected Cross‑Site Scripting flaw in the web‑based management interface of Cisco Identity Services Engine. An unauthenticated remote attacker can craft a link that, when followed by a legitimate user of the interface, injects malicious script into the browser. The attacker can then execute arbitrary code in the context of the user’s session or read sensitive browser‑based information, undermining confidentiality and permitting session hijacking or other malicious actions.
Affected Systems
The vulnerability affects Cisco Identity Services Engine Software, specifically the web‑based management interface. Version information is not explicitly specified, indicating that all releases of the interface prior to Cisco’s remediation are susceptible.
Risk and Exploitability
The CVSS score of 6.1 denotes moderate severity, while an EPSS score of less than 1% reflects a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack vector requires only a simple crafted link, reachable over HTTP/HTTPS, and is limited to users who can access the management interface.
OpenCVE Enrichment