CVE-2026-20111: Cisco Prime Infrastructure Stored Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious code into specific data fields in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, an attacker must have valid administrative credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20111?
CVE-2026-20111 is classified as a high severity vulnerability due to the potential for exploitation via stored cross-site scripting attacks.
How do I fix CVE-2026-20111?
To remediate CVE-2026-20111, update your Cisco Prime Infrastructure to the latest available version that includes the security patch for this vulnerability.
Who is affected by CVE-2026-20111?
CVE-2026-20111 affects users of Cisco Prime Infrastructure who access its web-based management interface.
What type of attack can be executed using CVE-2026-20111?
CVE-2026-20111 allows an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack.
Is authentication required to exploit CVE-2026-20111?
Yes, exploitation of CVE-2026-20111 requires the attacker to be authenticated to the Cisco Prime Infrastructure.