Medium severity6.1NVD Advisory· Published Mar 4, 2026· Updated Jun 17, 2026
CVE-2026-20149
CVE-2026-20149
Description
A vulnerability in Cisco Webex could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability, and no customer action is needed. This vulnerability was due to improper filtering of user-supplied input. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to follow a malicious link. A successful exploit could have allowed the attacker to conduct an XSS attack against the targeted user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:cisco:webex:-:*:*:*:*:*:*:*
- Range: N/A
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.