4.8
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Description
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS attack against a user of the web-based management interface of an affected device.
These vulnerabilities are due to insufficient sanitization of user-supplied data that is stored in the web page. An attacker could exploit these vulnerabilities by convincing a user of the interface to click a specific link or view an affected web page. The injected script code may be executed in the context of the web-based management interface or allow the attacker to access sensitive browser-based information.
These vulnerabilities are due to insufficient sanitization of user-supplied data that is stored in the web page. An attacker could exploit these vulnerabilities by convincing a user of the interface to click a specific link or view an affected web page. The injected script code may be executed in the context of the web-based management interface or allow the attacker to access sensitive browser-based information.
Basic Information
ID
CVE-2026-20132
Source
cisco
Published
Apr 15, 2026 at 16:03
Affected Product
Vendor
Cisco
Product
Cisco Identity Services Engine Software
Version
3.1.0
Affected Versions
Cisco Cisco Identity Services Engine Software 3.1.0
Cisco Cisco Identity Services Engine Software 3.1.0 p1
Cisco Cisco Identity Services Engine Software 3.1.0 p3
Cisco Cisco Identity Services Engine Software 3.1.0 p2
Cisco Cisco Identity Services Engine Software 3.2.0
Cisco Cisco Identity Services Engine Software 3.1.0 p4
Cisco Cisco Identity Services Engine Software 3.1.0 p5
Cisco Cisco Identity Services Engine Software 3.2.0 p1
Cisco Cisco Identity Services Engine Software 3.1.0 p6
Cisco Cisco Identity Services Engine Software 3.2.0 p2
Cisco Cisco Identity Services Engine Software 3.1.0 p7
Cisco Cisco Identity Services Engine Software 3.3.0
Cisco Cisco Identity Services Engine Software 3.2.0 p3
Cisco Cisco Identity Services Engine Software 3.2.0 p4
Cisco Cisco Identity Services Engine Software 3.1.0 p8
Cisco Cisco Identity Services Engine Software 3.2.0 p5
Cisco Cisco Identity Services Engine Software 3.2.0 p6
Cisco Cisco Identity Services Engine Software 3.1.0 p9
Cisco Cisco Identity Services Engine Software 3.3 Patch 2
Cisco Cisco Identity Services Engine Software 3.3 Patch 1
Cisco Cisco Identity Services Engine Software 3.3 Patch 3
Cisco Cisco Identity Services Engine Software 3.4.0
Cisco Cisco Identity Services Engine Software 3.2.0 p7
Cisco Cisco Identity Services Engine Software 3.3 Patch 4
Cisco Cisco Identity Services Engine Software 3.4 Patch 1
Cisco Cisco Identity Services Engine Software 3.1.0 p10
Cisco Cisco Identity Services Engine Software 3.1.0 p1
Cisco Cisco Identity Services Engine Software 3.1.0 p3
Cisco Cisco Identity Services Engine Software 3.1.0 p2
Cisco Cisco Identity Services Engine Software 3.2.0
Cisco Cisco Identity Services Engine Software 3.1.0 p4
Cisco Cisco Identity Services Engine Software 3.1.0 p5
Cisco Cisco Identity Services Engine Software 3.2.0 p1
Cisco Cisco Identity Services Engine Software 3.1.0 p6
Cisco Cisco Identity Services Engine Software 3.2.0 p2
Cisco Cisco Identity Services Engine Software 3.1.0 p7
Cisco Cisco Identity Services Engine Software 3.3.0
Cisco Cisco Identity Services Engine Software 3.2.0 p3
Cisco Cisco Identity Services Engine Software 3.2.0 p4
Cisco Cisco Identity Services Engine Software 3.1.0 p8
Cisco Cisco Identity Services Engine Software 3.2.0 p5
Cisco Cisco Identity Services Engine Software 3.2.0 p6
Cisco Cisco Identity Services Engine Software 3.1.0 p9
Cisco Cisco Identity Services Engine Software 3.3 Patch 2
Cisco Cisco Identity Services Engine Software 3.3 Patch 1
Cisco Cisco Identity Services Engine Software 3.3 Patch 3
Cisco Cisco Identity Services Engine Software 3.4.0
Cisco Cisco Identity Services Engine Software 3.2.0 p7
Cisco Cisco Identity Services Engine Software 3.3 Patch 4
Cisco Cisco Identity Services Engine Software 3.4 Patch 1
Cisco Cisco Identity Services Engine Software 3.1.0 p10