Server-Side Request Forgery Vulnerability in Cisco Finesse Management Interface
CVE-2026-20362

7.2HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
7 October 2026

Badges

👾 Exploit Exists

What is CVE-2026-20362?

A vulnerability exists in Cisco Finesse's web-based management interface that allows unauthenticated remote attackers to perform server-side request forgery (SSRF) attacks. This issue stems from improper input validation for certain HTTP requests. An attacker can exploit this vulnerability by sending specially crafted HTTP requests to the affected device, potentially gaining access to limited sensitive information related to services associated with it.

Affected Version(s)

Cisco Finesse 12.6(1)

Cisco Finesse 12.6(1)ES1

Cisco Finesse 12.6(1)ES2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.