CVE-2026-20198
Received Received - Intake

Cross-Site Scripting in Cisco IMC Web Interface

Vulnerability report for CVE-2026-20198, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
cisco integrated_management_controller *
cisco 5000_series_enterprise_network_compute_systems *
cisco catalyst_8300_series_edge_ucpe *
cisco ucs_c-series_m5 *
cisco ucs_c-series_m6 *
cisco ucs_e-series_servers_m3 *
cisco ucs_e-series_servers_m6 *
cisco ucs_s-series_storage_servers *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC). It allows an authenticated remote attacker to trick a user into clicking a crafted link, which executes arbitrary script code in the victim's browser or accesses sensitive browser-based information. The flaw stems from insufficient validation of user input.

Detection Guidance

Detecting this XSS vulnerability requires checking if your Cisco IMC web interface is running a vulnerable version. Review the Cisco advisory for affected product versions and compare against your deployed software. No direct detection commands are provided in the resources.

Impact Analysis

An attacker could exploit this to execute malicious scripts in your browser session, potentially stealing sensitive data like session cookies or credentials. It may also allow unauthorized access to browser-stored information, compromising the security of the affected Cisco IMC interface.

Compliance Impact

This XSS vulnerability could potentially expose sensitive browser-based information, which may impact compliance with standards like GDPR (data protection) and HIPAA (healthcare data privacy) if exploited to access or manipulate protected data.

Mitigation Strategies

Immediately upgrade to the fixed software releases specified in the Cisco advisory for your affected product. Cisco states no workarounds are available, so patching is required. Verify the upgrade by checking the software version against the advisory's fixed release list.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20198. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart