CVE-2026-20184 PUBLISHED

Cisco Webex Meetings Certificate Validation Vulnerability

Assigner: cisco
Reserved: 08.10.2025 Published: 15.04.2026 Updated: 16.04.2026

A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service.

This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service endpoint and supplying a crafted token. A successful exploit could have allowed the attacker to gain unauthorized access to legitimate Cisco Webex services.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Cisco
Product Cisco Webex Meetings
Versions Default: unknown
  • Version 39.7.7 is affected
  • Version 39.9 is affected
  • Version 40.4.10 is affected
  • Version 39.6 is affected
  • Version 40.6.2 is affected
  • Version 39.8.2 is affected
  • Version 39.8.4 is affected
  • Version 40.1 is affected
  • Version 39.11 is affected
  • Version 39.7.4 is affected
  • Version 39.9.1 is affected
  • Version 40.4 is affected
  • Version 40.6 is affected
  • Version 39.7 is affected
  • Version 39.8 is affected
  • Version 39.8.3 is affected
  • Version 40.2 is affected
  • Version 39.10 is affected
  • Version 42.6 is affected
  • Version 42.7 is affected
  • Version 42.8 is affected
  • Version 42.9 is affected
  • Version 42.10 is affected
  • Version 42.11 is affected
  • Version 42.12 is affected
  • Version 43.1 is affected
  • Version 43.2 is affected
  • Version 43.3 is affected
  • Version 43.4 is affected
  • Version 43.4.1 is affected
  • Version 43.4.2 is affected
  • Version 43.5.0 is affected
  • Version 43.6.0 is affected
  • Version 43.6.1 is affected
  • Version 43.7 is affected
  • Version 43.8 is affected
  • Version 43.9 is affected
  • Version 43.10 is affected
  • Version 43.11 is affected
  • Version 43.12 is affected
  • Version 44.1 is affected
  • Version 44.2 is affected
  • Version 44.3 is affected
  • Version 44.4 is affected
  • Version 44.5 is affected
  • Version 44.6 is affected
  • Version 44.7 is affected
  • Version 44.8 is affected
  • Version 44.9 is affected
  • Version 44.10 is affected
  • Version 44.11 is affected
  • Version 44.12 is affected
  • Version 45.1 is affected
  • Version 45.2 is affected
  • Version 45.3 is affected
  • Version 45.4 is affected

Exploits

The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.

References

Problem Types

  • Improper Certificate Validation cwe