CVE-2026-20362
Cisco Finesse Server-Side Request Forgery Vulnerability
CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated with the affected device.
| CWE | CWE-918 |
| Vendor | cisco |
| Product | cisco finesse |
| Ecosystems | |
| Industries | NetworkingTelecommunications |
| Published | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for cisco cisco finesse
Be the first to know when new high vulnerabilities affecting cisco cisco finesse are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
Cisco / Cisco Finesse
12.6(1) 12.6(1)ES1 12.6(1)ES2 12.6(1)ES3 12.6(1)ES4 12.6(1)ES5 12.6(1)ES6 12.6(1)ES7 12.6(1)ES7_ET 12.6(2) 12.6(1)ES8 12.6(1)ES9 12.6(2)ES1 12.6(1)ES10 12.6(1)ES11 12.6(2)ES2 12.6(2)ES3 12.6(2)ES4 12.6(2)ES5 15.0(1) 12.6(2)ES6 15.0(1)ES202508 15.0(1)ES202511 15.0(1)ES202602 15.0(1)SU1 12.6(2)ES7 15.0(1)SU2 12.6(2)ES8