CVE-2026-20184 is a critical vulnerability in Cisco Webex Services affecting the SSO integration with Control Hub. The flaw stems from improper certificate validation, which allows an unauthenticated remote attacker to impersonate any user by supplying a crafted token to a service endpoint, potentially granting complete unauthorized access to legitimate Webex services. The vulnerability carries a CVSS score of 9.8 (Critical) with a network-based attack vector requiring no privileges or user interaction, indicating high severity across all impact categories including confidentiality, integrity, and availability. The attack complexity is low, making exploitation straightforward for threat actors with basic network access. Current exploitation status indicates this vulnerability is not actively being exploited in the wild, with no public exploit code confirmed available and no inclusion on the KEV or Hot List databases. However, the moderate FAUCET Risk Score of 55.0 suggests organizations should prioritize patching given the ease of exploitation and the severity of potential impact, despite the low current threat prevalence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cisco | Cisco Webex Meetings | 39.10, 39.11, 39.6, 39.7, 39.7.4, 39.7.7, 39.8, 39.8.2, 39.8.3, 39.8.4, 39.9, 39.9.1, 40.1, 40.2, 40.4, 40.4.10, 40.6, 40.6.2, 42.10, 42.11, 42.12, 42.6, 42.7, 42.8, 42.9, 43.1, 43.10, 43.11, 43.12, 43.2, 43.3, 43.4, 43.4.1, 43.4.2, 43.5.0, 43.6.0, 43.6.1, 43.7, 43.8, 43.9, 44.1, 44.10, 44.11, 44.12, 44.2, 44.3, 44.4, 44.5, 44.6, 44.7, 44.8, 44.9, 45.1, 45.2, 45.3, 45.4CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.