CVE-2026-20230
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- EPSS probability
- 88.20%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-918
- Published
- 2026-06-03
- Last modified
- 2026-07-01
Affected products
- Cisco Cisco Unified Communications Manager
- Cisco Cisco Unified Communications Manager
- Cisco Cisco Unified Communications Manager
- Cisco Cisco Unified Communications Manager
- Cisco Cisco Unified Communications Manager
- Cisco Cisco Unified Communications Manager
- Cisco Cisco Unified Communications Manager
- Cisco Cisco Unified Communications Manager
Weakness type
Related vulnerabilities
- CVE-2026-88001 — Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
- CVE-2026-87999 — Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
- CVE-2026-87996 — Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
- CVE-2026-19233 — CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized...
- CVE-2026-86771 — Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num
- CVE-2026-87821 — Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch
- CVE-2026-79635 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-57866 — Apache Impala: Secrets Exfiltration via SSRF