Executive brief
Cisco Webex Meetings is a cloud-based video conferencing and collaboration platform. A security flaw in its web interface could have allowed an attacker to execute malicious scripts in a user's browser if the user clicked on a specifically crafted link. This could lead to the unauthorized access of sensitive session information or the performance of actions on behalf of the user within the Webex application.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the web-based user interface of Cisco Webex Meetings due to insufficient validation of user-supplied input. An unauthenticated, remote attacker can exploit this by persuading a target user to click a malicious link containing a crafted payload. If successful, the attacker can execute arbitrary script code in the context of the affected interface or access sensitive browser-based information, such as session cookies. As this is a cloud-based service, Cisco has applied the fix server-side, and no customer action is required.
Affected products
- Cisco Webex Meetings Cloud-based service prior to June 3, 2026
Timeline
- 2026-06-03: disclosed
- 2026-06-03: patched: Cisco addressed the vulnerability in the cloud service.
- 2026-06-03: advisory