CVE-2026-20132 affects Cisco Identity Services Engine (ISE) web-based management interface and consists of multiple stored and reflected cross-site scripting (XSS) vulnerabilities. The flaws stem from insufficient sanitization of user-supplied data, enabling authenticated attackers with administrative write privileges to inject malicious scripts that execute within the management interface context. This could allow attackers to access sensitive browser-based information or compromise administrative sessions. The vulnerability carries a CVSS score of 4.8 (Medium severity) with a network-based attack vector requiring no special access complexity. However, exploitation demands high-level administrative privileges and user interaction, as victims must click a malicious link or visit a specially crafted web page. The impact is limited to low confidentiality and integrity risks with no availability impact. The vulnerability shows minimal exploitation activity and community attention. It is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, has no publicly available proof-of-concept code on the Hot List, and ranks lower than 99.9 percent of all CVEs in real-world exploit prevalence based on EPSS scoring. Organizations should apply patches when available but should not prioritize this above higher-severity threats.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.