CVE-2026-20184: Cisco Webex Meetings Certificate Validation Vulnerability
A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service endpoint and supplying a crafted token. A successful exploit could have allowed the attacker to gain unauthorized access to legitimate Cisco Webex services.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20184?
CVE-2026-20184 is classified as a high severity vulnerability due to its potential for exploitation to impersonate users.
How do I fix CVE-2026-20184?
To mitigate CVE-2026-20184, update your Cisco Webex Services and Cisco Webex Meetings to the latest version provided by Cisco.
What are the consequences of CVE-2026-20184?
The consequences of CVE-2026-20184 include unauthorized access and impersonation of users within Cisco Webex Services.
Who is affected by CVE-2026-20184?
Any organization using Cisco Webex Services or Cisco Webex Meetings with single sign-on integration is potentially affected by CVE-2026-20184.
Is authentication required to exploit CVE-2026-20184?
No, CVE-2026-20184 allows an unauthenticated remote attacker to exploit the vulnerability, making it particularly dangerous.