CVE 4.8 MEDIUM

Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Cross-Site Scripting Vulnerability_CVE-2026-20109

4.8 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Description

Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. 

These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have valid administrative credentials.

Basic Information

ID CVE-2026-20109
Source cisco
Published Jan 21, 2026 at 16:26

Affected Product

Vendor Cisco
Product Cisco Packaged Contact Center Enterprise
Version 12.5(1)
Affected Versions Cisco Cisco Packaged Contact Center Enterprise 12.5(1)
Cisco Cisco Packaged Contact Center Enterprise 11.0(1)
Cisco Cisco Packaged Contact Center Enterprise 12.0(1)
Cisco Cisco Packaged Contact Center Enterprise 11.0(2)
Cisco Cisco Packaged Contact Center Enterprise 11.5(1)
Cisco Cisco Packaged Contact Center Enterprise 10.5(1)
Cisco Cisco Packaged Contact Center Enterprise 10.5(2)
Cisco Cisco Packaged Contact Center Enterprise 11.6(2)
Cisco Cisco Packaged Contact Center Enterprise 10.5(1)_ES7
Cisco Cisco Packaged Contact Center Enterprise 11.6(1)
Cisco Cisco Packaged Contact Center Enterprise 10.5(2)_ES8
Cisco Cisco Packaged Contact Center Enterprise 12.6(1)
Cisco Cisco Packaged Contact Center Enterprise 12.5(2)
Cisco Cisco Packaged Contact Center Enterprise 12.6(2)
Cisco Cisco Packaged Contact Center Enterprise 15.0(1)
Cisco Cisco Unified Contact Center Enterprise 12.6(1)ES3
Cisco Cisco Unified Contact Center Enterprise 12.6(1)ES1
Cisco Cisco Unified Contact Center Enterprise 12.6(1)
Cisco Cisco Unified Contact Center Enterprise 12.6(1)ES2
Cisco Cisco Unified Contact Center Enterprise 12.6(1)SecurityPatch
Cisco Cisco Unified Contact Center Enterprise 12.5(1)ES1
Cisco Cisco Unified Contact Center Enterprise 12.5(1)
Cisco Cisco Unified Contact Center Enterprise 12.6(1)ES4
Cisco Cisco Unified Contact Center Enterprise 11.0(1)
Cisco Cisco Unified Contact Center Enterprise 10.5(1)
Cisco Cisco Unified Contact Center Enterprise 12.0(1)
Cisco Cisco Unified Contact Center Enterprise 10.5
Cisco Cisco Unified Contact Center Enterprise 11.0
Cisco Cisco Unified Contact Center Enterprise 11.5
Cisco Cisco Unified Contact Center Enterprise 12.6(2)
Cisco Cisco Unified Contact Center Enterprise 12.6(2)ES1
Cisco Cisco Unified Contact Center Enterprise 12.6(2)ES2
Cisco Cisco Unified Contact Center Enterprise 15.0(1)
Cisco Cisco Unified Contact Center Enterprise 12.6(2)ES3
Cisco Cisco Unified Contact Center Enterprise 15.0(1)ET01
Cisco Cisco Unified Contact Center Enterprise 15.0(1)_SP1
Cisco Cisco Unified Contact Center Enterprise 15.0(1)ES202508
Cisco Cisco Unified Contact Center Enterprise 12.6(2)_ES

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.