Cisco Contact Center XSS Flaws Require Admin Credentials
Cisco has disclosed multiple medium-severity cross-site scripting vulnerabilities in Packaged CCE and Unified CCE. The flaws affect the web-based management interface and require valid administrative credentials to exploit.

Key takeaways
- Cisco disclosed multiple cross-site scripting vulnerabilities in the web-based management interface of Packaged CCE and Unified CCE.
- A successful attack could execute script code in the context of the affected interface or expose sensitive browser-based information.
- Exploitation requires valid administrative credentials, according to Cisco.
- Cisco released software updates to address the issue, and no workarounds are available.
Research integrity
Intro
Cisco has published a security advisory for multiple cross-site scripting (XSS) vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE).
According to Cisco, these issues stem from improper validation of user-supplied input. An authenticated remote attacker could abuse the flaws to inject malicious code into specific interface pages. Cisco assigns the advisory a Medium security impact rating and tracks the issues as CVE-2026-20055 and CVE-2026-20109.
Why it matters
Even when a vulnerability requires authentication, XSS in an administrative interface should not be treated lightly. If exploited successfully, these flaws could allow script execution in the context of the affected interface or expose sensitive browser-based information tied to an administrative session.
For organizations that rely on Cisco contact center infrastructure, administrative consoles often sit close to operational workflows, user management, and broader service configuration. That makes browser-side attacks against those consoles particularly relevant for defenders monitoring privileged access paths.
Just as important, Cisco states that no workarounds are available. That means organizations cannot rely on a simple configuration change to neutralize risk and should instead focus on patch planning and privileged access hygiene.
Who should care
This alert matters most to:
- Security teams responsible for Cisco collaboration and contact center environments
- Administrators managing Packaged CCE or Unified CCE deployments
- SOC and vulnerability management teams tracking authenticated application flaws
- IT leaders reviewing risk around privileged web-based management interfaces
If your environment includes these Cisco products, confirm whether the affected management interfaces are deployed and whether administrative access is tightly controlled.
Practical response
Defenders should take a measured, operational response:
- Review Cisco's advisory immediately and identify whether your Packaged CCE or Unified CCE versions are affected.
- Apply Cisco's software updates as soon as change management allows, since Cisco has released fixes.
- Prioritize administrative account security, because exploitation requires valid administrative credentials.
- Audit access to the web-based management interface and verify that only authorized users can reach it.
- Monitor privileged sessions and browser-based admin activity for unusual behavior, especially around interface interactions and account use.
- Document exposure and remediation status for internal risk tracking, particularly if the platforms support customer-facing contact center operations.
Because Cisco explicitly says there are no workarounds, postponing updates may leave affected systems exposed until patches are installed.
Bottom line
Cisco's latest advisory highlights medium-severity XSS risk in Packaged CCE and Unified CCE administrative web interfaces. The vulnerabilities require valid administrative credentials, but they can still affect sensitive browser-side activity and trusted admin workflows.
For defenders, the path is straightforward: verify exposure, restrict and review administrative access, and deploy Cisco's updates without unnecessary delay.
Frequently asked questions
What products are affected?
Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) are affected in their web-based management interface.
Does this require prior access?
Yes. Cisco states an attacker must have valid administrative credentials to exploit these vulnerabilities.
Are there mitigations besides patching?
Cisco says there are no workarounds that address these vulnerabilities, so applying the vendor-provided software updates is the recommended response.




