Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug in Meeting Management
ID: 22be0a50-51e6-53d0-9502-e662f82d25a3
STIX ID: report--22be0a50-51e6-53d0-9502-e662f82d25a3
Feed Name: The Register (Security)
Threat Score
Cisco released a patch for a critical 9.9-rated privilege escalation vulnerability (CVE-2025-20156) in Cisco Meeting Management caused by improper REST API authorization; an authenticated low-privilege attacker could gain admin access to edge nodes. Most releases are affected with no workaround available—users should upgrade (3.9→3.9.1, migrate 3.8 and earlier; 3.10 unaffected); Cisco has not observed active exploitation yet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
