CVE-2026-20362
Received Received - Intake

Server-Side Request Forgery in Cisco Finesse Web Interface

Vulnerability report for CVE-2026-20362, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated with the affected device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 28 associated CPEs
Vendor Product Version / Range
Cisco Cisco Finesse 12.6(1)
Cisco Cisco Finesse 12.6(1)ES1
Cisco Cisco Finesse 12.6(1)ES2
Cisco Cisco Finesse 12.6(1)ES3
Cisco Cisco Finesse 12.6(1)ES4
Cisco Cisco Finesse 12.6(1)ES5
Cisco Cisco Finesse 12.6(1)ES6
Cisco Cisco Finesse 12.6(1)ES7
Cisco Cisco Finesse 12.6(1)ES7_ET
Cisco Cisco Finesse 12.6(2)
Cisco Cisco Finesse 12.6(1)ES8
Cisco Cisco Finesse 12.6(1)ES9
Cisco Cisco Finesse 12.6(2)ES1
Cisco Cisco Finesse 12.6(1)ES10
Cisco Cisco Finesse 12.6(1)ES11
Cisco Cisco Finesse 12.6(2)ES2
Cisco Cisco Finesse 12.6(2)ES3
Cisco Cisco Finesse 12.6(2)ES4
Cisco Cisco Finesse 12.6(2)ES5
Cisco Cisco Finesse 15.0(1)
Cisco Cisco Finesse 12.6(2)ES6
Cisco Cisco Finesse 15.0(1)ES202508
Cisco Cisco Finesse 15.0(1)ES202511
Cisco Cisco Finesse 15.0(1)ES202602
Cisco Cisco Finesse 15.0(1)SU1
Cisco Cisco Finesse 12.6(2)ES7
Cisco Cisco Finesse 15.0(1)SU2
Cisco Cisco Finesse 12.6(2)ES8

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a server-side request forgery (SSRF) vulnerability in Cisco Finesse's web-based management interface. It allows unauthenticated remote attackers to send crafted HTTP requests to the device, exploiting improper input validation. A successful exploit may let attackers access limited sensitive information from services linked to the affected device.

Detection Guidance

This vulnerability can be detected by monitoring network traffic for unusual HTTP requests targeting the Cisco Finesse web-based management interface. Check for crafted requests that attempt to access internal services or sensitive endpoints. Use network scanning tools like Nmap to identify exposed Cisco Finesse instances and verify their versions against the affected releases.

Impact Analysis

An attacker could exploit this to obtain limited sensitive information from services associated with the Cisco Finesse device. This could include internal network details or other restricted data, potentially leading to further attacks or data exposure.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access to sensitive information through SSRF attacks. Exposure of limited sensitive data may violate data protection requirements under these regulations.

Mitigation Strategies

Immediately upgrade Cisco Finesse to the fixed versions: 15.0(1) SU3 (February 2027) for Cisco Finesse, 15.0(1)ES202701 (January 2027) for Packaged CCE and Unified CCE, and 15.0(1) SU2 (February 2027) for Unified CCX. If upgrades are not immediately possible, restrict access to the web-based management interface via network segmentation or firewall rules to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20362. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart