Cross-site scripting in Cisco Identity Services Engine (ISE) - CVE-2026-20309
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
The vulnerability exists due to improper input validation in the web-based management interface of Cisco Identity Services Engine when processing user-supplied input. A remote attacker can persuade a user of the interface to click a crafted link to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
User interaction is required to click the crafted link.