AI analysis
Cisco Finesse has an unauthenticated server-side request forgery flaw in its web-based management interface, tracked as CVE-2026-20362 (CWE-918). The issue is improper validation of specific HTTP requests, so a remote attacker can send a crafted request to an affected device without credentials or user interaction. A successful exploit can obtain limited sensitive information about services associated with that device and can also affect integrity in a limited way (CVSS 3.1 base score 7.2, scope changed); availability is not impacted. Organizations running Cisco Finesse as part of contact-center deployments are affected; the advisory data does not name fixed or vulnerable version ranges. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Treat the Finesse web management interface as untrusted-network reachable until patched: restrict it to management networks, block it from the internet, and apply the Cisco fix for CVE-2026-20362 as soon as the vendor advisory lists fixed releases. Review access logs for unexpected HTTP requests from the interface toward internal services, and do not rely on a public exploit existing before you harden exposure.
Affected
| Cisco Finesse (web-based management interface) | — |
Estimated exposure
moderateOn the order of thousands of contact-center servers (exact count unknown) — Cisco Finesse is the standard agent desktop shipped with Cisco Unified and Packaged Contact Center Enterprise and Contact Center Express, so deployments are enterprise contact-center servers rather than a mass consumer install base;…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated with the affected device.