CVE-2018-0436 is a high-severity vulnerability in Cisco Webex Teams that allows an authenticated, remote attacker with administrator or compliance officer privileges to view and modify data belonging to other organizations. The vulnerability stems from insufficient checks for user-to-organization account associations. With a CVSS score of 8.7, this flaw has a high impact on confidentiality and integrity, requiring high privileges but low attack complexity. While no customer data was impacted, there is no public exploit code available, nor is it known to be actively exploited, despite some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.6.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_teams:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.