CVE-2026-20175

Finesse: External Control of File Name or Path (CVE-2026-20175)

mediumEPSS 0.2%

Affected

  • Cisco/Finesse 15.0(1)SU1..*

Description

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerability is due to insufficient validation of user-supplied input for HTTP requests that are sent to an affected device. An attacker who has knowledge of the address of the affected device could exploit this vulnerability by persuading a user to click a crafted link that contains the affected device address. A successful exploit could allow the attacker to conduct browser-based attacks and execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

CiscoFinesse
15.0(1)SU1

Metrics

6.1
Source: nvd-v3
6.9 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-06-03 18:16 UTC
CWE-73

Weakness classes (CWE)

  • CWE-73Base

    External Control of File Name or Path

    The product allows user input to control or influence paths or file names that are used in filesystem operations.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-07-22 19:10 UTC· nvd@nist.gov
    • Translation: Title: Cisco Finesse de Cisco, Description: Una vulnerabilidad en Cisco Finesse podría permitir a un atacante remoto no autenticado cargar archivos arbitrarios desde ubicaciones remotas en una sesión de usuario activa en un dispositivo afectado, lo que posiblemente llevaría a ataques basados en el navegador. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario para las solicitudes HTTP que se envían a un dispositivo afectado. Un atacante que tenga conocimiento de la dirección del dispositivo afectado podría explotar esta vulnerabilidad persuadiendo a un usuario para que haga clic en un enlace manipulado que contenga la dirección del dispositivo afectado. Un exploit exitoso podría permitir al atacante realizar ataques basados en el navegador y ejecutar código de script arbitrario en el contexto de la interfaz afectada o acceder a información sensible en el dispositivo afectado.

Linked advisories