PT-2026-33093 · Cisco · Webex Meetings
Published
2026-04-15
·
Updated
2026-05-12
·
CVE-2026-20184
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Webex Meetings versions 39.6 through 45.4
Description
An issue in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services allows an unauthenticated, remote attacker to impersonate any user within the service. This occurs due to improper certificate validation. An attacker can exploit this by connecting to a service endpoint and providing a crafted token, potentially gaining unauthorized access to legitimate Cisco Webex services.
Recommendations
For versions 39.6 through 45.4, apply the latest patches released by Cisco.
Update SAML certificates and rotate them immediately in Control Hub.
Review identity provider configurations to ensure proper security.
Fix
RCE
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webex Meetings