What is CVE-2026-20198?
This vulnerability exists in the web-based management interface of Cisco IMC, allowing an authenticated remote attacker to perform an XSS attack due to insufficient input validation. Users are advised to apply security updates from Cisco to mitigate the risk.
Azərbaycanca: Bu boşluq Cisco IMC veb idarəetmə interfeysində aşkarlanmış və autentifikasiya olunmuş uzaq hücumçuya XSS hücumu həyata keçirməyə imkan verir. Bu, istifadəçi girişinin yetərsiz yoxlanılması səbəbindən baş verir. Təsirə məruz qalmamaq üçün istifadəçilərə Cisco-dan təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Cisco
FAQ2
What security issue does CVE-2026-20198 cause in the Cisco IMC interface?
This vulnerability allows an authenticated remote attacker to perform an XSS attack in the web-based management interface.
What is recommended for users to protect against CVE-2026-20198?
Users are advised to apply security updates from Cisco.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.