CVE-2026-20232
A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of another user. To exploit this vulnerability, the attacker must have valid user credentials on the affected system.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS probability
- 0.21%
- CWE
- CWE-80
- Published
- 2026-08-19
- Last modified
- 2026-08-19
Affected products
- Cisco Cisco Industrial Ethernet Switches
- Cisco Cisco Industrial Ethernet Switches
- Cisco Cisco Industrial Ethernet Switches
- Cisco Cisco Industrial Ethernet Switches
- Cisco Cisco Industrial Ethernet Switches
- Cisco Cisco Industrial Ethernet Switches
- Cisco Cisco Industrial Ethernet Switches
- Cisco Cisco Industrial Ethernet Switches
Weakness type
Related vulnerabilities
- CVE-2026-52774 — Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki
- CVE-2026-52773 — Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki
- CVE-2026-32773 — Apache Spark: XSS Vulnerability in Spark Web 3.5.4
- CVE-2026-82838 — Default webserver configuration with incorrect CSP
- CVE-2026-55696 — PrivateBin: Stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction
- CVE-2026-5218 — HTML Injection in Softtr's E-Commerce Pack
- CVE-2026-5389 — justhtml before 1.13.0 XSS via code fence breakout
- CVE-2026-35163 — OctoPrint: XSS in Suppressed Command Notifications