CVE-2026-20117: Multiple Cisco Contact Center Products Cross-Site Scripting Vulnerabilities
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability exists because the web-based management interface of an affected system does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20117?
CVE-2026-20117 is classified as a high severity vulnerability.
How do I fix CVE-2026-20117?
To mitigate CVE-2026-20117, users should upgrade to the latest version of Cisco Unified Contact Center Express that includes the security patch.
What types of attacks can CVE-2026-20117 facilitate?
CVE-2026-20117 can facilitate cross-site scripting (XSS) attacks against users of affected Cisco products.
Who is impacted by CVE-2026-20117?
Any organization using Cisco Unified Contact Center Express is potentially impacted by CVE-2026-20117.
Is authentication required for exploiting CVE-2026-20117?
No, CVE-2026-20117 can be exploited by unauthenticated, remote attackers.