Cross-Site Scripting Vulnerability in Cisco Webex
CVE-2026-20149
6.1MEDIUM
What is CVE-2026-20149?
A vulnerability in Cisco Webex enabled the potential for unauthenticated, remote attackers to execute cross-site scripting (XSS) attacks. This oversight stemmed from inadequate filtering of user-supplied input, making it possible for an attacker to craft a malicious link. When a targeted user followed this link, it could lead to the execution of harmful scripts in their browser. Fortunately, Cisco has remedied this issue, and no further action is required from customers.
Affected Version(s)
Cisco Webex Meetings