Record summary

CVE-2026-20198 has a selected CVSS score of 4.8 (medium).

Description

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Cisco Enterprise NFV Infrastructure Software

Browse Cisco / Cisco Enterprise NFV Infrastructure Software

Default status: unknown

CVE List4.1.1affected
3.9.1affected
3.5.2affected
3.12.2affected
3.6.2affected
3.9.2affected
3.11.3affected
3.11.1affected
3.5.1affected
3.3.1affected
3.10.2affected
3.12.1baffected
Showing 12 of 72 version ranges

Cisco Unified Computing System (Standalone)

Browse Cisco / Cisco Unified Computing System (Standalone)

Default status: unknown

CVE List4.0(2g)affected
3.1(2i)affected
3.1(1d)affected
4.0(4i)affected
4.1(1c)affected
4.0(2c)affected
4.0(1e)affected
4.0(2h)affected
4.0(4h)affected
4.0(1h)affected
4.0(2l)affected
3.1(3g)affected
Showing 12 of 156 version ranges

Cisco Unified Computing System E-Series Software (UCSE)

Browse Cisco / Cisco Unified Computing System E-Series Software (UCSE)

Default status: unknown

CVE List3.2.7affected
3.2.6affected
3.2.4affected
3.2.10affected
3.2.2affected
3.2.3affected
3.2.1affected
3.2.11.1affected
3.2.8affected
3.1.1affected
3.1.2affected
3.1.4affected
Showing 12 of 31 version ranges

References

2