Executive brief
A vulnerability in the Cisco Webex Contact Center Desktop Agent could have allowed an attacker to perform cross-site scripting (XSS) attacks. By tricking a user into clicking a malicious link, an attacker could steal sensitive browser data, including login credentials and active session information. Cisco has already updated the cloud service, and no customer action is required to resolve the issue.
Technical details
A reflected cross-site scripting (XSS) vulnerability (CWE-80) exists in the Desktop Agent component of Cisco Webex Contact Center due to improper neutralization of HTML and script-related tags. An unauthenticated remote attacker can exploit this by persuading a user to follow a specially crafted malicious link. If successful, the attacker can execute arbitrary script code in the context of the victim's browser session, potentially allowing the theft of authentication tokens or session cookies. As this is a cloud-based service, Cisco has applied the fix server-side, and no manual patching is required by end users.
Affected products
- Cisco Webex Contact Center Cloud-based service prior to April 2026 update
Timeline
- 2026-04-15: disclosed
- 2026-04-15: advisory
- 2026-04-15: patched: Cisco addressed the issue in the cloud service; no customer action needed.