PT-2026-33093 · Cisco · Webex Meetings

Published

2026-04-15

·

Updated

2026-04-18

·

CVE-2026-20184

CVSS v2.0

10

Critical

AV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Webex Meetings versions 39.6 through 45.4
Description An issue in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could allow an unauthenticated, remote attacker to impersonate any user within the service. This occurs due to improper certificate validation. An attacker could exploit this by connecting to a service endpoint and supplying a crafted token, resulting in unauthorized access to legitimate Cisco Webex services.
Recommendations Apply the latest patches released by Cisco for versions 39.6 through 45.4. Perform a manual certificate update in Control Hub. Rotate SAML certificates and review identity provider configurations.

Fix

RCE

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2026-05532
CVE-2026-20184

Affected Products

Webex Meetings