CVE-2026-20362: Cisco Finesse
High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated with the affected device.
Affected products
- Cisco Cisco Finesse: version 12.6(1) only; version 12.6(1)ES1 only; version 12.6(1)ES2 only; version 12.6(1)ES3 only; version 12.6(1)ES4 only; version 12.6(1)ES5 only; …
Published 2026-10-07. Last modified 2026-10-08.