logo

Cisco Meeting Management Vulnerability Let Remote Attacker Upload Arbitrary Files

ID: d9395360-0123-517f-b159-678072e31b17

STIX ID: report--d9395360-0123-517f-b159-678072e31b17

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-02-05

Date Updated: 2026-04-21

Author: Abinaya

...
...

Cisco Meeting Management contains a high-severity input-validation vulnerability (CVE-2026-20098) in its Certificate Management web interface that permits authenticated users with at least 'video operator' privileges to upload malicious files processed as the root account, enabling full device takeover; affected releases are 3.12 and earlier and administrators are urged to upgrade to 3.12.1 MR immediately as no workarounds exist and no in-the-wild exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.