CISCO Security Advisory

Published Date: June 25, 2026

CVE: CVE-2026-20175

Advisory Summary

▶️🔐 Cisco Finesse Remote File Inclusion Vulnerability (CVE-2026-20175) Overview:

A medium-severity security vulnerability has been identified in Cisco Finesse that allows an unauthenticated, remote attacker to execute remote file inclusion attacks. This arises from inadequate validation of user input in HTTP requests handled by the Finesse platform. Exploitation can occur if an attacker convinces a user to click on a specially crafted link containing the target device’s address. Upon successful exploitation, attackers can execute arbitrary scripts within the victim’s browser session or access sensitive information exposed through the affected interface.

✅ Recommended Action:
Organizations running Cisco Finesse should urgently apply the released security patches provided by Cisco to mitigate this vulnerability effectively. Due to the lack of workarounds, timely update deployment is critical to prevent potential exploitation.

This vulnerability underscores the importance of validating user input in web-facing systems to avert remote file inclusion risks that can compromise session integrity and data confidentiality.

Reference: Vendor Advisory