Cisco Enterprise Chat and Emai... Note

Cisco Enterprise Chat and Email Lite Agent File Upload Vulnerability

A vulnerability exists in Cisco Enterprise Chat and Email (ECE)'s Lite Agent feature. This flaw could allow a remote attacker with valid agent credentials to launch browser-based attacks. The vulnerability stems from insufficient validation of files uploaded during file upload. An attacker could exploit this by uploading a file containing malicious scripts or HTML code. When accessed by other users, this malicious code would execute in their browsers. This could allow an attacker to perform browser-based attacks on other users. Cisco has released software updates to patch this vulnerability. There are no available workarounds to mitigate the risks. A Cisco Security Advisory details the vulnerability. The security impact is rated as Medium, and the CVE assigned is CVE-2026-20172.