Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.1
Cisco Unified CCX Web Interface Allows Unauthenticated XSS Attacks
CVE-2026-20117
Summary
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an attacker to inject malicious code into the interface, potentially allowing them to steal sensitive information or take control of a user's browser. This vulnerability does not require authentication, making it a concern for public-facing systems. Cisco should be contacted for a patch or workaround.
Original title
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) att...
Original description
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
This vulnerability exists because the web-based management interface of an affected system does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
This vulnerability exists because the web-based management interface of an affected system does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
nvd CVSS3.1
6.1
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 11 Mar 2026 · Updated: 13 Mar 2026 · First seen: 11 Mar 2026