---
id: CVE-2026-20362
title: "A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.\r\n\r\nThis vulnerability is due to impr…"
summary: "A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.\r\n\r\nThis vulnerability is due to impr…"
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-918
vendor: Cisco
product: Cisco Finesse
affected:
  - finesse 12.6(1)
  - finesse 12.6(1)ES1
  - finesse 12.6(1)ES2
  - finesse 12.6(1)ES3
  - finesse 12.6(1)ES4
  - finesse 12.6(1)ES5
  - finesse 12.6(1)ES6
  - finesse 12.6(1)ES7
  - finesse 12.6(1)ES7_ET
  - finesse 12.6(2)
  - finesse 12.6(1)ES8
  - finesse 12.6(1)ES9
  - finesse 12.6(2)ES1
  - finesse 12.6(1)ES10
  - finesse 12.6(1)ES11
  - finesse 12.6(2)ES2
  - finesse 12.6(2)ES3
  - finesse 12.6(2)ES4
  - finesse 12.6(2)ES5
  - finesse 15.0(1)
  - finesse 12.6(2)ES6
  - finesse 15.0(1)ES202508
  - finesse 15.0(1)ES202511
  - finesse 15.0(1)ES202602
  - finesse 15.0(1)SU1
  - finesse 12.6(2)ES7
  - finesse 15.0(1)SU2
  - finesse 12.6(2)ES8
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T17:16:55.303'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20362'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-mmSuyugS
    label: psirt@cisco.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T16:38:22.255Z'
---

## Overview

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.

This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated with the affected device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
