Back to overview

CVE-2026-20184

CRITICAL
9.8
CVSS 3.1
Description
A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service endpoint and supplying a crafted token. A successful exploit could have allowed the attacker to gain unauthorized access to legitimate Cisco Webex services.

Metadata

CVE ID
CVE-2026-20184
State
PUBLISHED
Assigner
cisco
Reserved
2025-10-08 11:59 UTC
Published
2026-04-15 16:03 UTC
Last updated
2026-04-16 19:07 UTC
Primary CWE
CWE-295
Improper Certificate Validation
Vendor / Product
Cisco / Cisco Webex Meetings
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Cisco Cisco Webex Meetings 39.7.7, 39.9, 40.4.10, 39.6 …
Weakness (CWE)
CWESourceDescription
CWE-295 cna Improper Certificate Validation
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview