CVE-2026-20098
A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary files, execute arbitrary commands, and elevate privileges to root on an affected system.
This vulnerability is due to improper input validation in certain sections of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to upload arbitrary files to the affected system.
Leer descripción completaMostrar menos
The malicious files could overwrite system files that are processed by the root system account and allow arbitrary command execution with root privileges. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of video operator.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.42%
- Percentil entre todas las CVEs puntuadas: 34
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement90 % - Impacto principal
T1505.003Web Shellpersistence85 % - Impacto secundario
T1059Command and Scripting Interpreterexecution90 % - Impacto secundario
T1068Exploitation for Privilege Escalationprivilege escalation85 %
Acceso remoto autenticado (PR:L) a servicio web de Cisco: T1210. Carga de archivos arbitrarios que sobrescriben ficheros del sistema ejecutados como root permite web shell (T1505.003), ejecución de comandos (T1059) y escalada a privilegios root (T1068).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-434
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-20098",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-20098",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-02-05T04:55:17.537048Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@cisco.com",
"affectedData": [
{
"vendor": "Cisco",
"product": "Cisco Meeting Management",
"versions": [
{
"status": "affected",
"version": "CMM3.4.0"
},
{
"status": "affected",
"version": "CMM3.2.0"
},
{
"status": "affected",
"version": "CMM2.9.1"
},
{
"status": "affected",
"version": "CMM2.9.0"
},
{
"status": "affected",
"version": "CMM3.1.0"
},
{
"status": "affected",
"version": "CMM3.5.0"
},
{
"status": "affected",
"version": "CMM3.6.0"
},
{
"status": "affected",
"version": "CMM3.6.1"
},
{
"status": "affected",
"version": "CMM3.7.0"
},
{
"status": "affected",
"version": "CMM3.8.0"
},
{
"status": "affected",
"version": "CMM3.9.0"
},
{
"status": "affected",
"version": "CMM3.10.0"
},
{
"status": "affected",
"version": "CMM3.9.1"
},
{
"status": "affected",
"version": "CMM3.11.0"
},
{
"status": "affected",
"version": "CMM3.12.0"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-02-04T17:16:14.107",
"references": [
{
"url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmm-file-up-kY47n8kK",
"tags": [
"Vendor Advisory"
],
"source": "psirt@cisco.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"description": [
{
"lang": "en",
"value": "CWE-434"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary files, execute arbitrary commands, and elevate privileges to root on an affected system.\r\n\r\nThis vulnerability is due to improper input validation in certain sections of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to upload arbitrary files to the affected system. The malicious files could overwrite system files that are processed by the root system account and allow arbitrary command execution with root privileges. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of video operator."
},
{
"lang": "es",
"value": "Una vulnerabilidad en la función de Gestión de Certificados de Cisco Meeting Management podría permitir a un atacante remoto autenticado cargar archivos arbitrarios, ejecutar comandos arbitrarios y elevar privilegios a root en un sistema afectado.\n\nEsta vulnerabilidad se debe a una validación de entrada incorrecta en ciertas secciones de la interfaz de gestión basada en web. Un atacante podría explotar esta vulnerabilidad enviando una solicitud HTTP manipulada a un sistema afectado. Un exploit exitoso podría permitir al atacante cargar archivos arbitrarios en el sistema afectado. Los archivos maliciosos podrían sobrescribir archivos del sistema que son procesados por la cuenta de sistema root y permitir la ejecución de comandos arbitrarios con privilegios de root. Para explotar esta vulnerabilidad, el atacante debe tener credenciales válidas para una cuenta de usuario con al menos el rol de operador de video."
}
],
"lastModified": "2026-06-17T10:17:05.603",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:meeting_management:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "697B0AD4-CC33-4DC8-B14B-5162C8230693",
"versionEndExcluding": "3.12.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@cisco.com"
}