← All Advisories

Cisco Webex SSO Integration with Control Hub Performed Improper Certificate Validation, Allowing Unauthenticated Attackers to Impersonate Any User Within the Service Prior to Patching

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-20184

Key Details

CVECVE-2026-20184
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-06-17
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-295 (Improper Certificate Validation)

What to Know

A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service.

This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service endpoint and supplying a crafted token. A successful exploit could have allowed the attacker to gain unauthorized access to legitimate Cisco Webex services. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-20184
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-20184