Junglewise Threat Intelligence

CVE-2026-20132: Cisco Identity Services Engine XSS in web-based management interface

CVE-2026-20132 · Severity: medium · CVSS 4.8 · Published 2026-04-15

Technologies: Cisco Identity Services Engine. Vendors: Cisco.

Executive brief

Cisco Identity Services Engine (ISE), a platform used to manage secure network access, contains vulnerabilities in its web management interface. An attacker with administrative privileges could inject malicious scripts that execute when other administrators view certain pages or click specific links. This could lead to the theft of sensitive browser-based information or unauthorized actions performed in the context of the victim's session.

Technical details

Multiple cross-site scripting (XSS) vulnerabilities exist in the web-based management interface of Cisco Identity Services Engine (ISE) due to insufficient sanitization of user-supplied data. An authenticated, remote attacker with high privileges (administrative write access) can exploit these flaws by injecting malicious script code into the interface. The attack can be delivered via a stored vector (where the script is saved on the server) or a reflected vector (requiring the victim to click a crafted link). Successful exploitation allows the execution of arbitrary script code in the victim's browser session, potentially leading to the disclosure of sensitive information like session tokens. Cisco has released software updates to address these issues; no workarounds are available.

Affected products

  • Cisco Identity Services Engine (ISE) 3.1 and earlier; 3.2 before 3.2 Patch 8; 3.3 before 3.3 Patch 5; 3.4 before 3.4 Patch 2

Timeline

  • 2026-04-15: disclosed: Initial public release of Cisco advisory
  • 2026-04-15: patched: Fixed releases made available by Cisco

References

Related threats