cbcvebase.
CVE-2026-20085
published 2026-04-01

CVE-2026-20085: A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.

Affected

256 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software
ciscocisco_enterprise_nfv_infrastructure_software