Executive brief
A vulnerability in the web-based version of Cisco Webex could have allowed attackers to redirect users to malicious websites. By tricking a user into clicking a specially crafted link, an attacker could send them to a fraudulent site designed to steal credentials or distribute malware. Cisco has already updated the cloud-based service, so no action is required from customers.
Technical details
An open redirect vulnerability (CWE-601) existed in the browser-based Cisco Webex App due to improper input validation of URL parameters in HTTP requests. An unauthenticated remote attacker could exploit this by persuading a user to click a maliciously crafted URL. If successful, the application would redirect the user's browser to an arbitrary external domain. This type of flaw is typically used in phishing campaigns to lend credibility to malicious links by using a trusted domain as the initial landing point. Cisco has patched the vulnerability in their cloud-hosted environment; no manual software updates are required for end users.
Affected products
- Cisco Webex App (browser-based) Cloud-based (all versions prior to June 2026 update)
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory
- 2026-06-17: patched: Cisco addressed the issue in the cloud-based service.