Cisco Unified CCX Editor Authentication Bypass Vulnerability
CVE-2025-20358 is a critical authentication bypass vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified Contact Center Express (Unified CCX). The flaw is caused by improper or missing authentication in the communication path between the CCX Editor and the Unified CCX server. An attacker can redirect the editor’s authentication flow to an attacker-controlled server and return crafted responses that cause the CCX Editor to incorrectly treat authentication as successful. Once this trust boundary is bypassed, the editor grants administrative permissions related to script creation and execution. Successful exploitation allows the attacker to create and execute arbitrary scripts on the underlying operating system of the affected Unified CCX server as an internal non-root user account.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Affected products & vendors
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
Recent activity
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical authentication bypass vulnerability in Cisco Unified Contact Center Express (CCX) due to improper authentication between the CCX Editor and server, allowing attackers to execute arbitrary scripts as a non-root user.
A critical missing-authentication flaw in Cisco Unified Contact Center Express (UCCX) involving CCX Editor-to-server communication, enabling unauthenticated remote attackers to bypass authentication and execute arbitrary scripts/commands on the underlying OS as a non-root internal user.
A critical Cisco Unified CCX Editor authentication-bypass leading to administrative permissions and the ability to create/execute arbitrary scripts on the underlying OS (effectively command execution / privilege escalation).
A critical authentication bypass vulnerability in Cisco Unified CCX that can let an attacker redirect authentication to a malicious server and execute arbitrary scripts as a non-root internal user.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.