CVE-2026-20172Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct browser-based attacks. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Agent. This vulnerability is due to inadequate validation of file contents during file upload operations. An attacker could exploit this vulnerability by uploading a file that contains malicious scripts or HTML code, which the application could make available to other users to access. A successful exploit could allow the attacker to execute the contents of that file in the browser of a user and conduct browser-based attacks. 

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-646

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-06); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-06: 2Mentions · 2026-05-07: 1Technical Details · 2026-05-06: 2Technical Details · 2026-05-07: 105-0605-07
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-062
Disclosure2
2026-05-071
General1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-20172 A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct browser-based attacks. To … https://www.cve.org/CVERecord?id=CVE-2026-20172

    Post summary

    The text announces CVE-2026-20172, describing an authenticated remote attack possibility on Cisco Enterprise Chat and Email’s Lite Agent via browser-based exploitation; no PoC, exploit code, patch, or active exploitation details are provided.

    00010121
    57.4K followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    General

    Cisco Enterprise Chat and Email Lite Agent File Upload Vulnerability (CVE-2026-20172) #Cisco #CiscoEnterpriseChatandEmail #CVE202620172 #CyberSecurity #FileUploadVulnerability https://www.systemtek.co.uk/?p=50917 https://t.co/6yQXaqPwa6

    Post summary

    The tweet merely announces a file‑upload vulnerability (CVE‑2026‑20172) in Cisco’s Chat and Email Lite Agent and provides links, with no further information on PoC, exploits, or mitigations.

    0000051
    1.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-20172 A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct browser-based attacks. To … https://www.cve.org/CVERecord?id=CVE-2026-20172 ----- Traducción: CVE-2026-20172 Una… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-20172 affecting Cisco ECE’s Lite Agent, detailing that an authenticated remote attacker can perform browser-based attacks; it does not provide a PoC, exploit code, patch information, or evidence of active exploitation.

    0000035
    75 followersView on X

Explore more