CVE-2026-20098Patch(cisco / meeting_management)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cisco meeting_management systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary files, execute arbitrary commands, and elevate privileges to root on an affected system. This vulnerability is due to improper input validation in certain sections of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to upload arbitrary files to the affected system. The malicious files could overwrite system files that are processed by the root system account and allow arbitrary command execution with root privileges. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of video operator.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • meeting_management

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 11 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 5 mentions (2026-02-05); latest day: 1
  • 12 total mentions across 6 days

Affected systems

Vendors
Products
meeting_management

Deep dive

Activity timeline12 mentions / 6d
01345Mentions · 2026-02-04: 2Mentions · 2026-02-05: 5Mentions · 2026-02-06: 1Mentions · 2026-02-09: 2Mentions · 2026-02-12: 1Mentions · 2026-03-03: 1Patch / Workaround · 2026-02-05: 4Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-04: 2Technical Details · 2026-02-05: 5Technical Details · 2026-02-06: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-12: 1Technical Details · 2026-03-03: 102-0402-0502-0602-0902-1203-03
Signal classification3 categories
Patch
650.0%
Disclosure
541.7%
General
18.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-042
Disclosure2
2026-02-055
Disclosure1Patch4
2026-02-061
Patch1
2026-02-092
General1Patch1
2026-02-121
Disclosure1
2026-03-031
Disclosure1
Full discourse12 posts
  • 듀나@selentia01
    Disclosure

    Cisco Meeting Management CVE-2026-20098 이거, 보안 공지 쪽에는 "임의 파일 업로드"로만 적혀 있는데, 실제로는 업로드 파일로 root가 처리하는 시스템 파일을 덮어쓸 수 있어서 RCE(원격 명령 실행)나 권한 상승까지 가능함 실제로 CVSS 8.8로 꽤 높은 편임 https://t.co/ajnIHYtiSc

    Post summary

    The post clarifies that Cisco Meeting Management CVE‑2026‑20098 allows arbitrary file upload that can overwrite system files, enabling remote code execution or privilege escalation, and notes a high CVSS score of 8.8.

    00020289
    203 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical vulnerability in Cisco Meeting Management (CVE-2026-20098) allows remote file uploads leading to root access. Update to release 3.12.1 MR or later immediately! Link: https://thedailytechfeed.com/critical-cisco-meeting-management-flaw-allows-remote-file-uploads-urgent-update-recommended/ #Security #Cisco #Update #Patch #Exploit #Threat #Risk #Bug #Alert #Network #IT #Admin #System #Tech #Insecure #Remote #Access #Hack #Cyber #Software

    Post summary

    This advisory announces a critical remote file upload vulnerability in Cisco Meeting Management (CVE-2026-20098) that could lead to root access, urging immediate patching to release 3.12.1 MR or later.

    0101073
    236 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Cisco CMM の脆弱性 CVE-2026-20098 が FIX:任意のファイル・アップロードとシステム乗っ取り https://iototsecnews.jp/2026/02/05/cisco-warns-of-meeting-management-flaw-enabling-arbitrary-file-upload-by-remote-attackers/ この問題の原因は、Cisco Meeting Management (CMM) の Web 管理画面で証明書を管理する機能が、外部から送られてくるファイルの情報を正しくチェックできていないことにあります。この入力検証の不備を悪用する攻撃者は、システムを乗っ取るための悪意あるプログラムや、上書きしてはいけないシステム・ファイルを送り込むことが可能になっています。ビデオ・オペレーターなどの低権限ユーザーであっても、この隙を突いて細工したリクエストを送ることで、サーバーの最上位権限である root 権限でコマンドを実行できるようになります。つまり、会議の管理をするための窓口が、システムの土台を操作する入り口になっています。ご利用のチームは、ご注意ください。 #Cisco #CVE202620098 #MeetingManagement #Vulnerability

    Post summary

    The passage discloses a critical input‑validation vulnerability (CVE‑2026‑20098) in Cisco Meeting Management that allows arbitrary file upload and root‑level execution, and urges teams to be aware, but it does not provide a PoC, exploit code, or evidence of active exploitation.

    01000125
    483 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Cisco ❗ CVE-2026-20119 ❗ CVE-2026-20098 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cisco-9/ https://t.co/K0F9AEs7HT

    Post summary

    The post lists two Cisco CVEs and provides a link for more information, but offers no details on exploitation, patches, or technical specifics.

    00010157
    6.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple vulnerabilities in #Cisco products, notably CVE-2026-20119 leading to unauthenticated DoS in #RoomOS Software and CVE-2026-20098 an improper input validation vulnerability in Meeting Management. For more information: https://sec.cloudapps.cisco.com/security/center/publicationListing.x #Patch #Patch #Patch

    Post summary

    Cisco has disclosed CVE-2026-20119 and CVE-2026-20098, detailing DoS and input validation flaws, and has provided a link directing users to patch information.

    01000228
    7.2K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Cisco Meeting Management flaw enables root-level takeover via arbitrary file upload (CVE-2026-20098) Cisco patched CVE-2026-20098 where improper input validation in the Certificate Management web interface lets an authenticated “video operator” (or higher) upload arbitrary files that get processed by root, enabling root command execution and full device compromise. Affected CMM 3.12 and earlier must upgrade to 3.12.1 MR or later—no workaround exists. 🎯 Target: Global/Enterprise (Cisco Meeting Management) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/cisco-meeting-management-upload-vulnerability/

    Post summary

    Cisco has patched CVE‑2026‑20098, a root‑level takeover vulnerability in Meeting Management caused by arbitrary file uploads. Affected users must upgrade to version 3.12.1 MR; no workaround is available.

    0001066
    192 followersView on X
  • CyberWarZone@cyberwarzo44531
    Patch

    ⚠️ Cisco has disclosed CVE-2026-20119 (unauthenticated DoS in RoomOS/TelePresence) and CVE-2026-20098 (authenticated arbitrary file upload → root in Meeting Management). Patch ASAP. No exploits seen yet. #Cisco #CVE #CyberSecurity #InfoSec #Vulnerability #PatchNow

    Post summary

    Cisco has disclosed two CVEs affecting RoomOS/TelePresence and Meeting Management, with patches available; no exploits reported yet.

    0000086
    26 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    報告者はNATOのペネトレチーム CVE-2026-20098 Cisco Meeting Management Arbitrary File Upload Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmm-file-up-kY47n8kK

    Post summary

    Cisco Meeting Management has a newly disclosed CVE-2026-20098 allowing arbitrary file uploads, reported by the NATO penetration team; a Cisco advisory link is provided, but no PoC, exploit, or active exploitation is indicated.

    00000583
    6.7K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Cisco & F5 patch high-severity bugs: unauth TelePresence DoS + Cisco Meeting Management root RCE Cisco fixed CVE-2026-20119 (unauthenticated remote DoS via crafted meeting invite) and CVE-2026-20098 (authenticated arbitrary file upload leading to root command execution in Cisco Meeting Management), while F5’s Feb 2026 advisories include high-rated BIG-IP/NGINX issues such as CVE-2026-22548 that can restart critical processes and disrupt traffic. 🎯 Target: Global/Enterprise (Cisco Collaboration + F5 BIG-IP/NGINX) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/cisco-f5-patch-high-severity-vulnerabilities/

    Post summary

    The article announces the release of patches for high‑severity bugs affecting Cisco Collaboration and F5 BIG‑IP/NGINX products, detailing specific CVEs and the nature of the vulnerabilities.

    0000052
    192 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Cisco Meeting Management flaw lets authenticated attackers upload arbitrary files and execute as root Cisco patched a high-severity CMM bug (CVE-2026-20098, CVSS 8.8) in the Certificate Management web interface where improper input validation allows a user with “video operator” (or higher) privileges to upload arbitrary files to root-handled paths, enabling root-level command execution. Update to CMM 3.12.1 MR and audit for suspicious crafted HTTP upload activity against the management interface. 🎯 Target: Global/Enterprise Collaboration (Cisco Meeting Management) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/cisco-meeting-management-vulnerability/

    Post summary

    Cisco disclosed a high‑severity flaw in Meeting Management allowing privileged users to upload arbitrary files and achieve root execution; they released a patch (CMM 3.12.1 MR) and advised auditing for suspicious uploads.

    0000043
    192 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-20098: HIGH] Vulnerability in Cisco Meeting Management allows an attacker to upload files, execute commands, and gain root privileges due to improper input validation in the web-based management in...#cve,CVE-2026-20098,#cybersecurity https://cvefind.com/CVE-2026-20098

    Post summary

    The tweet reports a high‑severity vulnerability in Cisco Meeting Management that allows attackers to upload files, execute commands, and gain root privileges due to improper input validation.

    0000074
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-20098 - High A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary files, execute arbitrary commands, and elev... https://www.thehackerwire.com/vulnerability/CVE-2026-20098/ https://t.co/706Eo9WpE8

    Post summary

    The post announces a high-severity CVE (CVE-2026-20098) affecting Cisco Meeting Management's Certificate Management, which permits authenticated remote attackers to upload files, execute commands, and elevate privileges.

    0000049
    113 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appciscomeeting_management---

Explore more