Junglewise Threat Intelligence

CVE-2026-20117: Cisco Unified CCX cross-site scripting in web management interface

CVE-2026-20117 · Severity: medium · CVSS 6.1 · Published 2026-03-11

Vendors: Cisco.

Executive brief

Cisco Unified Contact Center Express (Unified CCX) is a platform used by businesses to manage customer interactions and contact center operations. A security flaw in its web management interface could allow an attacker to trick a user into executing malicious scripts. If successful, the attacker could gain access to sensitive information stored in the user's browser or perform actions on the user's behalf within the management system.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) due to insufficient validation of user-supplied input. An unauthenticated, remote attacker can exploit this by persuading a user of the interface to click a specially crafted link. Successful exploitation allows the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information such as session cookies. Cisco has released software updates to address this vulnerability in version 15.0 ES02 and recommends migrating from older, unsupported versions.

Affected products

  • Cisco Unified Contact Center Express (Unified CCX) Up to and including 15.0(1)ES01

Timeline

  • 2026-03-11: advisory: Initial public release by Cisco
  • 2026-03-11: patched: Fixed in 15.0 ES02

References