Junglewise Threat Intelligence

CVE-2026-20233: Cisco Webex Meetings cross-site scripting in web-based UI

CVE-2026-20233 · Severity: medium · CVSS 6.1 · Published 2026-06-03

Vendors: Cisco.

Executive brief

Cisco Webex Meetings is a cloud-based video conferencing and collaboration platform. A security flaw in its web interface could have allowed an attacker to execute malicious scripts in a user's browser if the user clicked on a specifically crafted link. This could lead to the unauthorized access of sensitive session information or the performance of actions on behalf of the user within the Webex application.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the web-based user interface of Cisco Webex Meetings due to insufficient validation of user-supplied input. An unauthenticated, remote attacker can exploit this by persuading a target user to click a malicious link containing a crafted payload. If successful, the attacker can execute arbitrary script code in the context of the affected interface or access sensitive browser-based information, such as session cookies. As this is a cloud-based service, Cisco has applied the fix server-side, and no customer action is required.

Affected products

  • Cisco Webex Meetings Cloud-based service prior to June 3, 2026

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: patched: Cisco addressed the vulnerability in the cloud service.
  • 2026-06-03: advisory

References

Related threats