CVE-2026-5923

Summary

Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.

Affected Software

VendorProductVersion RangeStatus
HP Inc.Poly CCX0 < 9.50affected
HP Inc.Poly Edge E0 < 8.6.0affected
HP Inc.Poly Trio C600 < 9.5.0affected

Weaknesses

  • CWE-352: CWE-352 Cross-Site request forgery (CSRF)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References