CISCO has publicly disclosed an unauthenticated server‑side request forgery (SSRF) flaw in the Finesse web interface, tracked as CVE-2026-20362. The vulnerability is rated 7.2 on CVSSv3 and is said to affect Finesse deployments regardless of device configuration. Cisco notes that there is no known workaround, and patches are not due to ship until early 2027.
Details from the advisory place the flaw in the web‑based management interface, arising from improper input validation for certain HTTP requests. An unauthenticated attacker can send crafted requests that cause the server to make requests on the attacker’s behalf, potentially exposing limited sensitive information for services linked to the affected device. Horizon3 researchers Noah King and Brandon Peterson are credited with reporting the issue. The CVSS vector indicates the impact could extend beyond the Finesse component itself.
Affected versions include Finesse 12.6 and earlier, across multiple 12.6 ES releases, with fixed releases scheduled as follows: Finesse 15.0: 15.0(1)SU3 in February 2027 (migrate from 12.6 and earlier); Packaged CCE and Unified CCE 15.0: 15.0(1)ES202701 in January 2027; Unified CCX 15.0: 15.0(1)SU2 in February 2027 (12.5 and earlier must migrate).
Cisco advises upgrading to the listed releases when available and, in the interim, isolating the Finesse web interface from untrusted networks and monitoring outbound traffic for unusual requests. Cisco Unified Intelligence Center is not affected.