Webex SSO Flaw Lets Attackers Impersonate Users

Cisco fixed a Webex Services SSO flaw that breaks a basic trust assumption: an attacker can impersonate any user without privileges if the customer has not completed the post-patch certificate update. Patching the service alone is not enough here. The identity link between Webex Services and Control Hub still needs customer action to keep SSO working safely. The issue is CVE-2026-20184 in the SSO integration with Control Hub. Cisco says the flaw lets remote attackers supply a crafted token and gain unauthorized access to legitimate Cisco Webex services. Customers using SSO must upload a new SAML certificate for their identity provider to Control Hub to avoid service interruption. Cisco also patched three other critical flaws in Identity Services Engine, but those require administrative credentials and are a different risk class. The Webex issue is the one that changes the threat model for ordinary users, because it turns identity infrastructure into an impersonation path until the certificate update is done.

Part of the PlainSec briefing for 2026-04-16

Sources