Webex SSO impersonates any user, unauth (CVE-2026-20184)
CVE-2026-20184
CVE-2026-20184 lets unauthenticated attackers impersonate any user in Cisco Webex via SSO token validation flaw. Patch now in Control Hub to prevent full account takeover.
Patch now - CVE-2026-20184 is a critical authentication bypass in Cisco Webex Services that grants an unauthenticated remote attacker the ability to impersonate any legitimate user and compromise all organizational communications. Apply the update via Cisco Webex Control Hub immediately.
Overview
A critical security vulnerability in Cisco Webex Services could have allowed a remote attacker with no credentials to impersonate any legitimate user. The flaw, tracked as CVE-2026-20184, resided in the integration between single sign-on (SSO) and the Webex Control Hub. It has been assigned the maximum CVSS score of 9.8.
Vulnerability Details
The vulnerability was caused by improper certificate validation during the SSO process. Prior to being addressed, an attacker could exploit this by connecting to a specific service endpoint and supplying a specially crafted authentication token. Because the system did not properly validate this token, the attack would succeed without requiring any user interaction or prior access.
Impact
A successful exploit would grant the attacker unauthorized access to Cisco Webex services with the privileges of any user they chose to impersonate. This could lead to a complete compromise of organizational communications, including access to sensitive meetings, messages, files, and user data. The attack is network-based and requires no user interaction, making it highly severe.
Remediation and Mitigation
Cisco has released updates that address this vulnerability. Administrators must apply the provided patches through the Cisco Webex Control Hub interface. There are no known workarounds for this flaw; patching is the only effective mitigation.
To remediate:
- Log in to the Cisco Webex Control Hub.
- Navigate to the service settings and apply all available updates.
- Ensure the update process completes successfully across your organization’s Webex deployment.
Organizations should prioritize this update due to the critical severity and straightforward exploitation path.
Security Insight
This vulnerability highlights the acute risk in trust relationships between core identity services (like SSO) and application platforms. A single validation lapse at this integration point bypasses all other security layers, enabling total impersonation. Similar SSO and token validation flaws have been root causes in major breaches across other SaaS platforms, underscoring the need for rigorous, defense-in-depth security testing of authentication bridges.
Update - May 2026
Since the original April 15 advisory, Cisco released a fixed Webex Services build (v2026.03.2-107) on May 5, patching the SSO token validation flaw. No additional patches or workarounds have been issued for unsupported versions.
The CVE remains absent from CISA’s Known Exploited Vulnerabilities catalog as of mid-May, though monitoring continues. EPSS probability rose marginally from 0.00067 to 0.0007 (21st percentile), indicating low but stable threat-actor interest.
No related CVEs in the Webex Control Hub or broader SSO integration layer have been disclosed this month. Publicly reported exploitation is limited to PoC code published on May 10 by a Chinese researcher (Weibo handle @Sec_Alpha_0x3), demonstrating token replay against unpatched tenants. No signatures have been added to major IDS/IPS systems as of May 14.
Defenders should prioritize applying the May 5 build if not yet deployed, audit SSO session logs for anomalous token reuse patterns (e.g., identical JWT claims across different source IPs), and restrict Control Hub access by IP allowlist where feasible. Given the low EPSS and no KEV listing, urgency is moderate but should not delay patching in environments using SSO for admin access.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in...
An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root....
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox ...
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a...