CVE-2026-20117
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability exists because the web-based management interface of an affected system does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
EPSS 0.05% · 17.4th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Unified Contact Center Express | *, 11.6(1), 11.6(2) |
Exploit Intelligence
- CIRCL seen: CVE-2026-20117 (circl-sighting)
- CIRCL seen: CVE-2026-20117 (circl-sighting)
- cisco-sa-cc-xss-MrNAH5Jh (circl)
Timeline
- Mar 11, 2026 CVE Published
- Mar 11, 2026 PoC Published
- Mar 11, 2026 CVE Updated
- Mar 12, 2026 EPSS Score
- Mar 12, 2026 PoC Published
- Mar 13, 2026 EPSS Score
- Mar 14, 2026 EPSS Score
- Mar 15, 2026 EPSS Score
- Mar 16, 2026 EPSS Score
- Mar 17, 2026 EPSS Score
- Mar 18, 2026 EPSS Score
- Mar 19, 2026 EPSS Score