Get real-time updates on Telegram
CVE-2026-20362: Cisco Finesse 12.6(1), 12.6(1)ES1, 12.6(1)ES2, 12.6(1)ES3, 12.6(1)ES4, 12.6(1)ES5, 12.6(1)ES6, 12.6(1)ES7…
Affected technology
Cisco Finesse · 12.6(1), 12.6(1)ES1, 12.6(1)ES2, 12.6(1)ES3, 12.6(1)ES4, 12.6(1)ES5, 12.6(1)ES6, 12.6(1)ES7, 12.6(1)ES7_ET, 12.6(2), 12.6(1)ES8, 12.6(1)ES9, 12.6(2)ES1, 12.6(1)ES10, 12.6(1)ES11, 12.6(2)ES2, 12.6(2)ES3, 12.6(2)ES4, 12.6(2)ES5, 15.0(1), 12.6(2)ES6, 15.0(1)ES202508, 15.0(1)ES202511, 15.0(1)ES202602, 15.0(1)SU1, 12.6(2)ES7, 15.0(1)SU2, 12.6(2)ES8
Cisco
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
An unauthenticated, remote attacker could conduct server-side request forgery (SSRF) attacks through an affected device. Vendor/CNA’s CVSS 3.1 assessment (base score 7.2/10) rates confidentiality and integrity impact as low; availability impact as none.
- CWE
- CWE-918
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 18:01:36.740415+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-20362.html