← Vulnerability feed

Vulnerability record · CVE-2018-0436 · published 5 October 2018

CVE-2018-0436: Cisco webex teams improper access control vulnerability

Cisco · Webex Teams

A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The vulnerability exists because the affected software performs insufficient checks for associations between user accounts and organization accounts. An attacker who has administrator or compliance officer privileges for one organization account could exploit this vulnerability by using those privileges to view and modify data for another organization account. No customer data was impacted by this vulnerability.

8.7 CVSS 3.1 High EPSS 1.3% · top 31.0% CWE-284 · Improper access controlCWE-269 · Improper privilege management
8.7CVSS 3.1 base score, v2 5.5
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The vulnerability exists because the affected software performs insufficient checks for associations between user accounts and organization accounts. An attacker who has administrator or compliance officer privileges for one organization account could exploit this vulnerability by using those privileges to view and modify data for another organization account. No customer data was impacted by this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0436 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-20236Cisco webex teams inclusion from untrusted sphere vulnerabilityA vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary …EPSS 0.97%8.8CVE-2019-1939Cisco webex teams injection vulnerabilityA vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affec…EPSS 4.3%8.8CVE-2018-0387Cisco webex teams improper input validation vulnerabilityA vulnerability in Cisco Webex Teams (for Windows and macOS) could allow an unauthenticated, remote attacker to execute arbitrary code on the user's …EPSS 3.1%8.4CVE-2020-3535Cisco webex teams uncontrolled search path element vulnerabilityA vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to…EPSS 0.59%7.8CVE-2021-1536Cisco webex meetings desktop uncontrolled search path element vulnerabilityA vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and C…EPSS 0.33%7.8CVE-2021-1502Cisco webex meetings desktop memory buffer overflow vulnerabilityA vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to…EPSS 1.1%7.8CVE-2019-1636Cisco Webex Teams Windows client unsafe search path allows command executionThe Cisco Webex Teams (formerly Spark) Windows client uses unsafe search paths for its application URI, so it can load libraries from a directory con…EPSS 47%analysed7.4CVE-2020-3155Cisco intelligence proximity improper certificate validation vulnerabilityA vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, remote attacker to view or alte…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2018-0436), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.