Back

MEDIUM

Multiple Cisco Contact Center Products Cross-Site Scripting Vulnerabilities

Published Mar 11, 2026

Description

A vulnerability in the web-based management interface of  Cisco Finesse, Cisco Packaged Contact Center Enterprise (Packaged CCE), Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Unified Contact Center Express (Unified CCX), and Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability exists because the web-based management interface of an affected system does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner cisco
Published Mar 11, 2026
Updated Mar 11, 2026
Reserved Oct 8, 2025

CISA Vulnrichment

Updated Mar 11, 2026

NVD

Status Undergoing Analysis
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner cisco
Published Mar 11, 2026
Updated Mar 11, 2026

GitHub

No data