Ad

CVE-2026-20132

MEDIUM CVSS 3.1: 4.8
Updated Apr 17, 2026
Cisco
Parameter Value
CVSS 4.8 (MEDIUM)
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Cisco
Public PoC No

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS attack against a user of the web-based management interface of an affected device. These vulnerabilities are due to insufficient sanitization of user-supplied data that is stored in the web page. An attacker could exploit these vulnerabilities by convincing a user of the interface to click a specific link or view an affected web page.

The injected script code may be executed in the context of the web-based management interface or allow the attacker to access sensitive browser-based information.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
High
Admin privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1