{"id":"CVE-2026-20362","title":"A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.\r\n\r\nThis vulnerability is due to impr…","summary":"A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.\r\n\r\nThis vulnerability is due to impr…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","cwe":["CWE-918"],"vendor":"Cisco","product":"Cisco Finesse","affected":["finesse 12.6(1)","finesse 12.6(1)ES1","finesse 12.6(1)ES2","finesse 12.6(1)ES3","finesse 12.6(1)ES4","finesse 12.6(1)ES5","finesse 12.6(1)ES6","finesse 12.6(1)ES7","finesse 12.6(1)ES7_ET","finesse 12.6(2)","finesse 12.6(1)ES8","finesse 12.6(1)ES9","finesse 12.6(2)ES1","finesse 12.6(1)ES10","finesse 12.6(1)ES11","finesse 12.6(2)ES2","finesse 12.6(2)ES3","finesse 12.6(2)ES4","finesse 12.6(2)ES5","finesse 15.0(1)","finesse 12.6(2)ES6","finesse 15.0(1)ES202508","finesse 15.0(1)ES202511","finesse 15.0(1)ES202602","finesse 15.0(1)SU1","finesse 12.6(2)ES7","finesse 15.0(1)SU2","finesse 12.6(2)ES8"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T17:16:55.303","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20362","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-mmSuyugS","label":"psirt@cisco.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-07T16:38:22.255Z","slug":"CVE-2026-20362","body":"## Overview\n\nA vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.\r\n\r\nThis vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated with the affected device.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}