Cisco Meeting Management Vulnerability Let Remote Attacker Upload Arbitrary Files
ID: d9395360-0123-517f-b159-678072e31b17
STIX ID: report--d9395360-0123-517f-b159-678072e31b17
Feed Name: cybersecurityNews.com
Cisco Meeting Management contains a high-severity input-validation vulnerability (CVE-2026-20098) in its Certificate Management web interface that permits authenticated users with at least 'video operator' privileges to upload malicious files processed as the root account, enabling full device takeover; affected releases are 3.12 and earlier and administrators are urged to upgrade to 3.12.1 MR immediately as no workarounds exist and no in-the-wild exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
