Cross-Site Scripting Vulnerability in Cisco Webex Contact Center
CVE-2026-20170

6.1MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
15 April 2026

Badges

👾 Exploit Exists

What is CVE-2026-20170?

A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center allowed unauthenticated remote attackers to perform cross-site scripting attacks. This issue arose due to improper handling of HTML and script content. Successfully exploiting this vulnerability enabled attackers to steal sensitive browser information such as authentication and session data by tricking users into following malicious links. Cisco has rectified this issue in the Webex Contact Center service without requiring any action from customers.

Affected Version(s)

Cisco Webex Contact Center

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.