CVE-2026-20198: Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20198?
The severity of CVE-2026-20198 is rated as medium with a score of 4.8.
How can I fix CVE-2026-20198?
To fix CVE-2026-20198, ensure that you apply the latest security updates provided by Cisco for the Integrated Management Controller.
What type of attack is associated with CVE-2026-20198?
CVE-2026-20198 is associated with Cross-Site Scripting (XSS) attacks.
Who is affected by CVE-2026-20198?
CVE-2026-20198 affects users of the Cisco Integrated Management Controller web-based management interface.
What causes CVE-2026-20198?
CVE-2026-20198 is caused by insufficient validation of user input in the Cisco Integrated Management Controller.