{"id":"CVE-2026-20132","title":"Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative&nbsp;write privileges to conduct a stored cross-site scripting (XSS)…","summary":"Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative&nbsp;write privileges to conduct a stored cross-site scripting (XSS)…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"cisco","product":"identity_services_engine","affected":["identity_services_engine < 3.2.0","identity_services_engine = 3.2.0","identity_services_engine = 3.3.0","identity_services_engine = 3.4.0"],"patched":["identity_services_engine 3.2.0"],"published":"2026-04-15","updated":"2026-07-02","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20132","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-isexss-BS8ctE7U","label":"psirt@cisco.com"}],"tags":["nvd"],"epss":0.00173,"epssPercentile":0.07079,"ingestedAt":"2026-07-02T18:41:45.684Z","slug":"CVE-2026-20132","body":"## Overview\n\nMultiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative&nbsp;write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS attack against a user of the web-based management interface of an affected device.\r\n\r\nThese vulnerabilities are due to insufficient sanitization of user-supplied data that is stored in the web page. An attacker could exploit these vulnerabilities by convincing a user of the interface to click a specific link or view an affected web page. The injected script code may be executed in the context of the web-based management interface or allow the attacker to access sensitive browser-based information.\n\n## Affected\n\n- `identity_services_engine < 3.2.0`\n- `identity_services_engine = 3.2.0`\n- `identity_services_engine = 3.3.0`\n- `identity_services_engine = 3.4.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `identity_services_engine 3.2.0`","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}