---
id: CVE-2026-20112
title: >-
  A vulnerability in the web-based Cisco IOx application hosting environment
  management interface of Cisco IOS XE Software could allow an authenticated,
  remote attacker to conduct a stored cross-site scripting (XSS) attack against
  a user o…
summary: >-
  A vulnerability in the web-based Cisco IOx application hosting environment
  management interface of Cisco IOS XE Software could allow an authenticated,
  remote attacker to conduct a stored cross-site scripting (XSS) attack against
  a user o…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: Cisco
product: Cisco IOS XE Software
affected:
  - ios_xe_software 16.6.1
  - ios_xe_software 16.6.2
  - ios_xe_software 16.6.3
  - ios_xe_software 16.6.4
  - ios_xe_software 16.6.5
  - ios_xe_software 16.6.4a
  - ios_xe_software 16.6.5a
  - ios_xe_software 16.6.6
  - ios_xe_software 16.6.7
  - ios_xe_software 16.6.8
  - ios_xe_software 16.6.9
  - ios_xe_software 16.6.10
  - ios_xe_software 16.7.1
  - ios_xe_software 16.7.1a
  - ios_xe_software 16.7.1b
  - ios_xe_software 16.7.2
  - ios_xe_software 16.7.3
  - ios_xe_software 16.7.4
  - ios_xe_software 16.8.1
  - ios_xe_software 16.8.1a
  - ios_xe_software 16.8.1b
  - ios_xe_software 16.8.1s
  - ios_xe_software 16.8.1c
  - ios_xe_software 16.8.1d
  - ios_xe_software 16.8.2
  - ios_xe_software 16.8.1e
  - ios_xe_software 16.8.3
  - ios_xe_software 16.9.1
  - ios_xe_software 16.9.2
  - ios_xe_software 16.9.1a
  - ios_xe_software 16.9.1b
  - ios_xe_software 16.9.1s
  - ios_xe_software 16.9.3
  - ios_xe_software 16.9.4
  - ios_xe_software 16.9.5
  - ios_xe_software 16.9.5f
  - ios_xe_software 16.9.6
  - ios_xe_software 16.9.7
  - ios_xe_software 16.9.8
  - ios_xe_software 16.10.1
  - ios_xe_software 16.10.1a
  - ios_xe_software 16.10.1b
  - ios_xe_software 16.10.1s
  - ios_xe_software 16.10.1c
  - ios_xe_software 16.10.1e
  - ios_xe_software 16.10.1d
  - ios_xe_software 16.10.2
  - ios_xe_software 16.10.1f
  - ios_xe_software 16.10.1g
  - ios_xe_software 16.10.3
published: '2026-03-25'
updated: '2026-06-17'
sourceUpdated: '2026-06-17T10:17:07.890'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20112'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-xss-LpGkzwtJ
    label: psirt@cisco.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-03-27T15:03:38.829239Z'
ingestedAt: '2026-09-14T00:20:40.079Z'
epss: 0.00194
epssPercentile: 0.08044
---

## Overview

A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
 This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
