Cross-Site Scripting Vulnerability in Cisco Webex Contact Center
CVE-2026-20170
6.1MEDIUM
What is CVE-2026-20170?
A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center allowed unauthenticated remote attackers to perform cross-site scripting attacks. This issue arose due to improper handling of HTML and script content. Successfully exploiting this vulnerability enabled attackers to steal sensitive browser information such as authentication and session data by tricking users into following malicious links. Cisco has rectified this issue in the Webex Contact Center service without requiring any action from customers.
Affected Version(s)
Cisco Webex Contact Center