CVE-2026-20117Disclosure(cisco / unified_contact_center_express)

LOWCVSS 6.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability exists because the web-based management interface of an affected system does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unified_contact_center_express

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
unified_contact_center_express

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-13: 203-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-20117 A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct… https://www.cve.org/CVERecord?id=CVE-2026-20117 ----- Traducción: CVE-2026-20117 Una… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑20117, a vulnerability in Cisco Unified Contact Center Express’s web interface that could allow an unauthenticated, remote attacker to act, without providing a PoC, exploit, or patch details.

    0000039
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20117 A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct… https://www.cve.org/CVERecord?id=CVE-2026-20117

    Post summary

    The statement announces the existence of CVE‑2026‑20117 in Cisco Unified Contact Center Express, noting it allows unauthenticated remote attackers to interact with the web interface, but does not offer any PoC, exploitation details, or mitigation guidance.

    00000211
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appciscounified_contact_center_express---

Explore more