CVE-2026-20116: Cisco Unified Contact Center Express

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of  Cisco Finesse, Cisco Packaged Contact Center Enterprise (Packaged CCE), Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Unified Contact Center Express (Unified CCX), and Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability exists because the web-based management interface of an affected system does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

Affected products

  • Cisco Cisco Unified Contact Center Express: version 10.5(1)SU1 only; version 10.6(1) only; version 11.6(1) only; version 10.6(1)SU1 only; version 10.6(1)SU3 only; version 11.6(2) only; …

Published 2026-03-11. Last modified 2026-06-17.