CVE-2026-20178Disclosure(cisco / webex_web_app)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed. This vulnerability existed due to improper input validation of URL parameters in an HTTP request. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to click a crafted URL. A successful exploit could have allowed the attacker to redirect a user to a malicious website.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webex_web_app

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
webex_web_app

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-17: 2Technical Details · 2026-06-17: 206-17
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-20178 A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco… https://www.cve.org/CVERecord?id=CVE-2026-20178 ----- Traducción: CVE-2026-20178 Una… http://infoflow.cloud`

    Post summary

    A new CVE (CVE‑2026‑20178) affecting the Cisco Webex browser-based app is disclosed, indicating an unauthenticated, remote attacker could redirect users to malicious webpages, but no PoC, exploitation tool, or patch information is provided.

    0000066
    82 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20178 A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco… https://www.cve.org/CVERecord?id=CVE-2026-20178

    Post summary

    The post announces CVE‑2026‑20178, noting that an unauthenticated, remote attacker can redirect users to malicious webpages in the browser‑based Cisco Webex App; no PoC, exploit code, exploitation evidence, or mitigation is provided.

    00000242
    57.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appciscowebex_web_app---

Explore more