CNNVD-202602-683 Information

CNNVD ID

CNNVD-202602-683

CVE-2026-20098

  • CNNVD Published: 2026-02-04

Description (Chinese)

Cisco Meeting Management(CMM)是美国思科(Cisco)公司的一个 Cisco 本地视频会议平台 Cisco Meeting Server 的管理工具。 Cisco Meeting Management存在代码问题漏洞,该漏洞源于基于Web的管理界面中某些部分输入验证不当,可能导致上传任意文件、执行任意命令和权限提升至root。

Description (English)

Cisco Meeting Management (CMM) is the management tool for Cisco Local Videoconferencing platform of Cisco Corporation. There is a code gap in Cisco Meeting Management, which stems from the miscertification of certain parts of the Web-based management interface, which may lead to the uploading of arbitrary documents, the execution of arbitrary orders and the upgrading of privileges to root.

Hazard Level

Medium

Vulnerability Type

代码问题

Affected Vendor

思科

Published

2026-02-04

Last Modified

2026-02-24

References

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmm-file-up-kY47n8kK https://access.redhat.com/security/cve/cve-2026-20098

Patch

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmm-file-up-kY47n8kK

Share on: