Junglewise Threat Intelligence

CVE-2026-20198: Cisco Integrated Management Controller cross-site scripting

CVE-2026-20198 · Severity: medium · CVSS 4.8 · Published 2026-08-05

Technologies: Cisco Catalyst 8300 Series Edge uCPE. Vendors: Cisco.

Executive brief

Cisco Integrated Management Controller (IMC) is a web-based management interface used to administer Cisco server hardware and appliances. A cross-site scripting vulnerability in IMC could allow an authenticated attacker to trick a user into clicking a malicious link, potentially stealing session data or executing commands in the context of the victim's browser session.

Technical details

This vulnerability is a reflected or stored cross-site scripting (XSS) flaw (CWE-79) in the Cisco IMC web-based management interface stemming from insufficient input validation. The vulnerability requires an authenticated attacker with network access to the IMC interface and user interaction (the victim must click a crafted link). An attacker can exploit this to execute arbitrary JavaScript in the victim's browser, potentially accessing sensitive browser-based information, stealing session tokens, or performing administrative actions on behalf of the victim. Cisco has released fixed software versions for affected platforms; no workarounds are available.

Affected products

  • Cisco Integrated Management Controller Multiple versions affected; see fixed software table
  • Cisco UCS C-Series M5 Rack Server Earlier than 4.2(3r), 4.3 before 4.3(2.260020)
  • Cisco UCS C-Series M6 Rack Server Earlier than 4.2(3r), 4.3 before 4.3(6.260054), 6.0 before 6.0(2.260143)
  • Cisco UCS E-Series M3 Affected; see advisory
  • Cisco UCS E-Series M6 Affected; see advisory
  • Cisco UCS S-Series Storage Server Affected; see advisory
  • Cisco Catalyst 8300 Series Edge uCPE NFVIS 4.12, 4.15, 4.18, 26.1 affected; see advisory
  • Cisco 5000 Series ENCS NFVIS 4.12, 4.15 affected; see advisory

Timeline

  • 2026-08-05: disclosed: CVE-2026-20198 published
  • 2026-08-05: patched: Fixed releases available

References

Related threats