CVE-2026-20047

CWE-805 documents5 sources
Severity
4.8MEDIUM
EPSS
0.0%
top 97.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 15

Description

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Cisco Identity Services Engine Cross-Site Scripting Vulnerability2026-01-15
GHSA
GHSA-vgf7-qrg3-cm45: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could2026-01-15

📋Vendor Advisories

1
Cisco
Cisco Identity Services Engine Cross-Site Scripting Vulnerability2026-01-15

🕵️Threat Intelligence

1
Wiz
CVE-2026-20047 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-20047 (MEDIUM CVSS 4.8) | A vulnerability in the web-based ma | cvebase.io