📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global apt Government and Defense CRITICAL 38m Global general Technology / Consumer Protection MEDIUM 49m Global vulnerability Information Technology and Security CRITICAL 56m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 3h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h Global apt Government and Defense CRITICAL 38m Global general Technology / Consumer Protection MEDIUM 49m Global vulnerability Information Technology and Security CRITICAL 56m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 3h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h Global apt Government and Defense CRITICAL 38m Global general Technology / Consumer Protection MEDIUM 49m Global vulnerability Information Technology and Security CRITICAL 56m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 3h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h
Vulnerabilities

CVE-2026-20170

Medium
CWE-80 — Weakness Type
Published: Apr 15, 2026  ·  Modified: Apr 18, 2026  ·  Source: NVD
CVSS v3
6.1
🔗 NVD Official
📄 Description (English)

A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, remote attacker to conduct cross-site scripting attacks. Cisco has addressed this vulnerability in the Cisco Webex Contact Center service, and no customer action is needed.

This vulnerability existed because HTML and script content was not properly handled. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to follow a malicious link. A successful exploit could have allowed the attacker to steal sensitive information from the browser, including authentication and session information.

🤖 AI Executive Summary

CVE-2026-20170 is a cross-site scripting (XSS) vulnerability in Cisco Webex Contact Center's Desktop Agent that could allow unauthenticated attackers to steal sensitive information including authentication credentials and session tokens. The vulnerability requires user interaction (clicking a malicious link) and has a CVSS score of 6.1 (medium). Cisco has already addressed this vulnerability in their service, requiring no immediate customer action.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 24, 2026 05:37
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi organizations using Cisco Webex Contact Center for customer service operations, particularly in banking (SAMA-regulated institutions), telecommunications (STC, Mobily), government agencies (NCA, CITC), and healthcare sectors. The XSS vulnerability could compromise customer service representatives' sessions, leading to unauthorized access to sensitive customer data, financial information, and potentially regulatory violations. Organizations in the financial sector face the highest risk due to regulatory compliance requirements and sensitive customer data exposure.
🏢 Affected Saudi Sectors
Banking and Financial Services Telecommunications Government and Public Administration Healthcare Insurance Retail and E-commerce
⚖️ Saudi Risk Score (AI)
6.8
/ 10.0
🔧 Remediation Steps (English)
1. IMMEDIATE ACTIONS:
- Verify your Cisco Webex Contact Center deployment is running the latest patched version (Cisco has already deployed fixes to their cloud service)
- If using on-premises deployment, contact Cisco support to confirm patch availability for your version
- Educate users about phishing and malicious link risks through security awareness training
- Monitor for suspicious activity in contact center logs

2. DETECTION & MONITORING:
- Implement Web Application Firewall (WAF) rules to detect XSS payloads in Webex Contact Center traffic
- Monitor browser console logs for unexpected script execution
- Track authentication anomalies and unusual session activities
- Alert on multiple failed authentication attempts from single sessions

3. COMPENSATING CONTROLS:
- Enforce Content Security Policy (CSP) headers to restrict script execution
- Implement browser isolation technology for contact center agents
- Use multi-factor authentication (MFA) to reduce impact of credential theft
- Restrict Webex Contact Center access to corporate networks only
- Deploy endpoint detection and response (EDR) solutions on agent workstations

4. VERIFICATION:
- Confirm Cisco Webex Contact Center service version through admin console
- Test with known XSS payloads in controlled environment to verify patching
🔧 خطوات المعالجة (العربية)
1. الإجراءات الفورية:
- تحقق من أن نشر Cisco Webex Contact Center الخاص بك يعمل على أحدث إصدار مصحح (قامت Cisco بنشر الإصلاحات بالفعل في خدمتها السحابية)
- إذا كنت تستخدم نشر محلي، اتصل بدعم Cisco للتأكد من توفر الإصلاح لإصدارك
- قم بتثقيف المستخدمين حول مخاطر الرسائل المزيفة والروابط الضارة من خلال التدريب على الوعي الأمني
- راقب النشاط المريب في سجلات مركز الاتصال

2. الكشف والمراقبة:
- تطبيق قواعد جدار حماية تطبيقات الويب (WAF) للكشف عن حمولات XSS في حركة Webex Contact Center
- مراقبة سجلات وحدة التحكم بالمتصفح للتنفيذ غير المتوقع للبرامج النصية
- تتبع شذوذ المصادقة والأنشطة غير العادية للجلسة
- التنبيه على محاولات مصادقة متعددة فاشلة من جلسات واحدة

3. الضوابط البديلة:
- فرض رؤوس سياسة أمان المحتوى (CSP) لتقييد تنفيذ البرامج النصية
- تطبيق تكنولوجيا عزل المتصفح لوكلاء مركز الاتصال
- استخدام المصادقة متعددة العوامل (MFA) لتقليل تأثير سرقة بيانات الاعتماد
- تقييد الوصول إلى Cisco Webex Contact Center للشبكات الداخلية فقط
- نشر حلول الكشف والاستجابة للنقاط النهائية (EDR) على محطات عمل الوكيل

4. التحقق:
- تأكد من إصدار خدمة Cisco Webex Contact Center من خلال وحدة التحكم الإدارية
- اختبر باستخدام حمولات XSS المعروفة في بيئة محكومة للتحقق من الإصلاح
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.14.2.1 - Information security requirements for supplier relationships ECC 2024 A.5.1.1 - Policies for information security ECC 2024 A.14.2.5 - Supplier security incident management
🔵 SAMA CSF
SAMA CSF 1.1 - Governance and Risk Management SAMA CSF 2.2 - Information and Communications Technology Security SAMA CSF 3.1 - Detection and Analysis SAMA CSF 4.1 - Containment, Eradication and Recovery
🟡 ISO 27001:2022
ISO 27001:2022 A.5.1 - Policies for information security ISO 27001:2022 A.6.2 - Information security roles and responsibilities ISO 27001:2022 A.8.2 - Endpoint protection ISO 27001:2022 A.13.1 - Network security
🟣 PCI DSS v4.0.1
PCI DSS 6.5.7 - Cross-site scripting prevention PCI DSS 6.2 - Security patches and updates PCI DSS 7.1 - Limit access to system components
📊 CVSS Score
6.1
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionR — Required
ScopeC — Changed
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score6.1
CWECWE-80
EPSS0.06%
Exploit No
Patch ✗ No
Published 2026-04-15
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
6.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-80
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.