Home Cisco CVE-2025-20156
Back to Cisco

CVE-2025-20156

Cisco Meeting Management - REST API

Cisco CVSS 9.9 Updated March 16, 2026

Executive Risk Summary

"A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists due to a lack of proper authorization enforcement upon REST API users, allowing an attacker to gain administrator-level control over edge nodes managed by Cisco Meeting Management."

Operational Audit Arsenal

Target Type API Endpoint
Target Asset REST API
Standard Path Management Plane

Manual Verification Required

This is a non-Windows asset (Cisco). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

Moderate

Internal Work Notes

CVE-2025-20156: Privilege escalation vulnerability in Cisco Meeting Management REST API, requiring patching to prevent administrator-level access by low-privileged attackers.

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Related Cisco Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.