Cisco Webex Services Single Sign-On Impersonation Vulnerability

Vulnerability

A vulnerability exists in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services. This flaw could have allowed an unauthenticated, remote attacker to impersonate any user within the service. The issue arises from improper certificate validation, which could have been exploited by connecting to a service endpoint and supplying a crafted token. A successful exploit would have granted unauthorized access to legitimate Cisco Webex services.

Impact

Exploitation of this vulnerability could have led to unauthorized access to Cisco Webex services, allowing attackers to impersonate users.

Remediation

Cisco has fixed this vulnerability in the Webex service. Affected organizations using SSO integration must upload a new identity provider (IdP) SAML certificate to Control Hub. For more details, refer to the Webex help article on managing SSO integration in Control Hub.

Added: Apr 15, 2026, 5:35 PM
Updated: Apr 15, 2026, 5:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
6.0
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.