CVE-2020-3361: Cisco Webex Meetings

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to gain unauthorized access to a vulnerable Webex site. The vulnerability is due to improper handling of authentication tokens by a vulnerable Webex site. An attacker could exploit this vulnerability by sending crafted requests to a vulnerable Cisco Webex Meetings or Cisco Webex Meetings Server site. If successful, the attacker could gain the privileges of another user within the affected Webex site.

Affected products

  • Cisco Webex Meetings: up to and including 39.5.25; from 40.1.0, up to and including 40.4.10; version 40.6.0 only
  • Cisco Webex Meetings Server: before 4.0 (fixed in 4.0); version 4.0 only

Published 2020-06-18. Last modified 2026-06-17.