Executive brief
Cisco Integrated Management Controller (IMC) is a web-based management interface used to administer Cisco server hardware and appliances. A cross-site scripting vulnerability in IMC could allow an authenticated attacker to trick a user into clicking a malicious link, potentially stealing session data or executing commands in the context of the victim's browser session.
Technical details
This vulnerability is a reflected or stored cross-site scripting (XSS) flaw (CWE-79) in the Cisco IMC web-based management interface stemming from insufficient input validation. The vulnerability requires an authenticated attacker with network access to the IMC interface and user interaction (the victim must click a crafted link). An attacker can exploit this to execute arbitrary JavaScript in the victim's browser, potentially accessing sensitive browser-based information, stealing session tokens, or performing administrative actions on behalf of the victim. Cisco has released fixed software versions for affected platforms; no workarounds are available.
Affected products
- Cisco Integrated Management Controller Multiple versions affected; see fixed software table
- Cisco UCS C-Series M5 Rack Server Earlier than 4.2(3r), 4.3 before 4.3(2.260020)
- Cisco UCS C-Series M6 Rack Server Earlier than 4.2(3r), 4.3 before 4.3(6.260054), 6.0 before 6.0(2.260143)
- Cisco UCS E-Series M3 Affected; see advisory
- Cisco UCS E-Series M6 Affected; see advisory
- Cisco UCS S-Series Storage Server Affected; see advisory
- Cisco Catalyst 8300 Series Edge uCPE NFVIS 4.12, 4.15, 4.18, 26.1 affected; see advisory
- Cisco 5000 Series ENCS NFVIS 4.12, 4.15 affected; see advisory
Timeline
- 2026-08-05: disclosed: CVE-2026-20198 published
- 2026-08-05: patched: Fixed releases available