CVE-2026-20230 (GCVE-0-2026-20230)

Vulnerability from cvelistv5 – Published: 2026-06-03 16:09 – Updated: 2026-07-01 16:28
VLAI CISA Previdian
Title
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
Summary
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.
SSVC
Exploitation: active Automatable: no Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-03 00:00 UTC
CWE
  • CWE-918 - Server-Side Request Forgery (SSRF)
Impacted products
Vendor Product Version
Cisco Cisco Unified Communications Manager Affected: 14
Affected: 14SU1
Affected: 14SU2
Affected: 14SU3
Affected: 15
Affected: 15SU1
Affected: 14SU4
Affected: 14SU4a
Affected: 15SU1a
Affected: 15SU2
Affected: 15.0.1.13010-1
Affected: 15.0.1.13011-1
Affected: 15.0.1.13012-1
Affected: 15.0.1.13013-1
Affected: 15.0.1.13014-1
Affected: 15.0.1.13015-1
Affected: 15.0.1.13016-1
Affected: 15.0.1.13017-1
Affected: 15SU3a
Affected: 14SU5
Affected: 15SU4
Affected: 15SU4a
Create a notification for this product.
CISA
Known Exploited Vulnerability - GCVE BCP-07 Compliant

Vulnerability ID: CVE-2026-20230

Status: Confirmed

Status Updated: 2026-06-25 02:00 CEST

Exploited: Yes


Timestamps
First Seen: 2026-06-25
Asserted: 2026-06-25

Scope
Notes: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability | Affected: Cisco / Unified Communications Manager | Description: Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-06-28 | Known ransomware campaign use (KEV): Unknown | Notes (KEV): https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-cucm-ssrf-cXPnHcW.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20230

Evidence

Type: Vendor Report

Signal: Successful Exploitation

Confidence: 80%

Source: cisa-kev


Details
Cwes CWE-918
Feed CISA Known Exploited Vulnerabilities Catalog
Product Unified Communications Manager
Due Date 2026-06-28
Date Added 2026-06-25
Vendorproject Cisco
Vulnerabilityname Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
Knownransomwarecampaignuse Unknown

References

Created: 2026-10-02 08:09 CEST | Updated: 2026-10-02 08:09 CEST
Previdian
Known Exploited Vulnerability - GCVE BCP-07 Compliant

Vulnerability ID: CVE-2026-20230

Status: Confirmed

Status Updated: 2026-06-24 00:20 CEST

Exploited: Yes


Timestamps
First Seen: 2026-06-23
Asserted: 2026-06-23

Scope
Notes: Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability | Affected: Cisco / Cisco Unified Communications Manager | CVSS: 8.6 (HIGH) | EPSS: 0.882 | Used in malware: unknown | Listed 2 days ahead of CISA KEV | Not yet in CISA KEV: False

Evidence

Type: Public Report

Signal: Successful Exploitation

Confidence: 70%

Source: previdian


Details
Feed Previdian (previdian.com)
Title Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
Cve Id CVE-2026-20230
Vendor Cisco
Ghsa Id GHSA-FCV7-PCHJ-75C2
Product Cisco Unified Communications Manager
Added Date 2026-06-23T22:20:36.536Z
Cvss Score 8.6
Epss Score 0.882
Previous Ids
Cvss Severity HIGH
Virtual Patch True
Cvss Estimated False
Epss Percentile 0.99766
Used In Malware unknown
Vulnerability Id CVE-2026-20230
Ahead Of Cisa Kev
{
  "count": 2,
  "unit": "day"
}
Not Yet In Cisa Kev False

References

Created: 2026-10-02 09:09 CEST | Updated: 2026-10-02 09:09 CEST
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-20230",
                "options": [
                  {
                    "Exploitation": "active"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-06-03T00:00:00+00:00",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-06-26T03:55:19.730Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/"
          },
          {
            "tags": [
              "government-resource"
            ],
            "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20230"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unknown",
          "product": "Cisco Unified Communications Manager",
          "vendor": "Cisco",
          "versions": [
            {
              "status": "affected",
              "version": "14"
            },
            {
              "status": "affected",
              "version": "14SU1"
            },
            {
              "status": "affected",
              "version": "14SU2"
            },
            {
              "status": "affected",
              "version": "14SU3"
            },
            {
              "status": "affected",
              "version": "15"
            },
            {
              "status": "affected",
              "version": "15SU1"
            },
            {
              "status": "affected",
              "version": "14SU4"
            },
            {
              "status": "affected",
              "version": "14SU4a"
            },
            {
              "status": "affected",
              "version": "15SU1a"
            },
            {
              "status": "affected",
              "version": "15SU2"
            },
            {
              "status": "affected",
              "version": "15.0.1.13010-1"
            },
            {
              "status": "affected",
              "version": "15.0.1.13011-1"
            },
            {
              "status": "affected",
              "version": "15.0.1.13012-1"
            },
            {
              "status": "affected",
              "version": "15.0.1.13013-1"
            },
            {
              "status": "affected",
              "version": "15.0.1.13014-1"
            },
            {
              "status": "affected",
              "version": "15.0.1.13015-1"
            },
            {
              "status": "affected",
              "version": "15.0.1.13016-1"
            },
            {
              "status": "affected",
              "version": "15.0.1.13017-1"
            },
            {
              "status": "affected",
              "version": "15SU3a"
            },
            {
              "status": "affected",
              "version": "14SU5"
            },
            {
              "status": "affected",
              "version": "15SU4"
            },
            {
              "status": "affected",
              "version": "15SU4a"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.\r\n\r\nThis vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.\r\nNote: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.\r\nNote: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default."
        }
      ],
      "exploits": [
        {
          "lang": "en",
          "value": "The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerability that is described in this advisory.\r\n\r\nIn June 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco continues to strongly recommend that customers upgrade to a fixed software release to remediate this vulnerability."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
            "version": "3.1"
          },
          "format": "cvssV3_1"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-918",
              "description": "Server-Side Request Forgery (SSRF)",
              "lang": "en",
              "type": "cwe"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-01T16:28:16.838Z",
        "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "shortName": "cisco"
      },
      "references": [
        {
          "name": "cisco-sa-cucm-ssrf-cXPnHcW",
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW"
        }
      ],
      "source": {
        "advisory": "cisco-sa-cucm-ssrf-cXPnHcW",
        "defects": [
          "CSCws67331"
        ],
        "discovery": "EXTERNAL"
      },
      "title": "Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
    "assignerShortName": "cisco",
    "cveId": "CVE-2026-20230",
    "datePublished": "2026-06-03T16:09:45.961Z",
    "dateReserved": "2025-10-08T11:59:15.399Z",
    "dateUpdated": "2026-07-01T16:28:16.838Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-20230",
      "date": "2026-10-05",
      "epss": "0.882",
      "percentile": "0.99766"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unknown",
                "product": "Cisco Unified Communications Manager",
                "vendor": "Cisco",
                "versions": [
                  {
                    "status": "affected",
                    "version": "14"
                  },
                  {
                    "status": "affected",
                    "version": "14SU1"
                  },
                  {
                    "status": "affected",
                    "version": "14SU2"
                  },
                  {
                    "status": "affected",
                    "version": "14SU3"
                  },
                  {
                    "status": "affected",
                    "version": "15"
                  },
                  {
                    "status": "affected",
                    "version": "15SU1"
                  },
                  {
                    "status": "affected",
                    "version": "14SU4"
                  },
                  {
                    "status": "affected",
                    "version": "14SU4a"
                  },
                  {
                    "status": "affected",
                    "version": "15SU1a"
                  },
                  {
                    "status": "affected",
                    "version": "15SU2"
                  },
                  {
                    "status": "affected",
                    "version": "15.0.1.13010-1"
                  },
                  {
                    "status": "affected",
                    "version": "15.0.1.13011-1"
                  },
                  {
                    "status": "affected",
                    "version": "15.0.1.13012-1"
                  },
                  {
                    "status": "affected",
                    "version": "15.0.1.13013-1"
                  },
                  {
                    "status": "affected",
                    "version": "15.0.1.13014-1"
                  },
                  {
                    "status": "affected",
                    "version": "15.0.1.13015-1"
                  },
                  {
                    "status": "affected",
                    "version": "15.0.1.13016-1"
                  },
                  {
                    "status": "affected",
                    "version": "15.0.1.13017-1"
                  },
                  {
                    "status": "affected",
                    "version": "15SU3a"
                  },
                  {
                    "status": "affected",
                    "version": "14SU5"
                  },
                  {
                    "status": "affected",
                    "version": "15SU4"
                  },
                  {
                    "status": "affected",
                    "version": "15SU4a"
                  }
                ]
              }
            ],
            "source": "psirt@cisco.com"
          }
        ],
        "cisaActionDue": "2026-06-28",
        "cisaExploitAdd": "2026-06-25",
        "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset\u0027s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "cisaVulnerabilityName": "Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability",
        "configurations": [
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:-:*:*:*",
                    "matchCriteriaId": "9E708402-3D51-4165-8A97-2B3E68116553",
                    "versionEndExcluding": "14su6",
                    "versionStartIncluding": "14.0",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:session_management:*:*:*",
                    "matchCriteriaId": "321D5CC9-ECFC-42FD-AAB4-465E3BC399DA",
                    "versionEndExcluding": "14su6",
                    "versionStartIncluding": "14.0",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:-:*:*:*",
                    "matchCriteriaId": "EFBE275E-8043-4F8B-ABE8-48774CF11648",
                    "versionEndIncluding": "15su4a",
                    "versionStartIncluding": "15.0",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:session_management:*:*:*",
                    "matchCriteriaId": "06300542-9590-4FE0-8054-7BD15B2CB3BA",
                    "versionEndIncluding": "15su4a",
                    "versionStartIncluding": "15.0",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ]
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.\r\n\r\nThis vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.\r\nNote: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.\r\nNote: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default."
          },
          {
            "lang": "es",
            "value": "Una vulnerabilidad en Cisco Unified Communications Manager (Unified CM) y Cisco Unified Communications Manager Session Management Edition (Unified CM SME) podr\u00eda permitir a un atacante remoto no autenticado realizar ataques de falsificaci\u00f3n de petici\u00f3n del lado del servidor (SSRF) a trav\u00e9s de un dispositivo afectado.\nEsta vulnerabilidad se debe a una validaci\u00f3n de entrada incorrecta para peticiones HTTP espec\u00edficas. Un atacante podr\u00eda explotar esta vulnerabilidad enviando una petici\u00f3n HTTP manipulada a un dispositivo afectado. Un exploit exitoso podr\u00eda permitir al atacante escribir archivos en el sistema operativo subyacente que podr\u00edan usarse m\u00e1s tarde para elevar a root.\nNota: Cisco ha asignado a este aviso de seguridad una Calificaci\u00f3n de Impacto de Seguridad (SIR) de Cr\u00edtica en lugar de Alta, como indica la puntuaci\u00f3n. La raz\u00f3n es que la explotaci\u00f3n de esta vulnerabilidad podr\u00eda resultar en que un atacante eleve privilegios a root.\nNota: Para explotar esta vulnerabilidad, el servicio WebDialer debe estar habilitado. WebDialer est\u00e1 deshabilitado por defecto."
          }
        ],
        "id": "CVE-2026-20230",
        "lastModified": "2026-07-22T19:10:00.120",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
                "version": "3.1"
              },
              "exploitabilityScore": 3.9,
              "impactScore": 4.0,
              "source": "psirt@cisco.com",
              "type": "Secondary"
            }
          ],
          "ssvcV203": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "ssvcData": {
                "id": "CVE-2026-20230",
                "options": [
                  {
                    "exploitation": "active"
                  },
                  {
                    "automatable": "no"
                  },
                  {
                    "technicalImpact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-06-03T00:00:00+00:00",
                "version": "2.0.3"
              }
            }
          ]
        },
        "published": "2026-06-03T18:16:20.160",
        "references": [
          {
            "source": "psirt@cisco.com",
            "tags": [
              "Vendor Advisory"
            ],
            "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW"
          },
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "tags": [
              "Exploit",
              "Third Party Advisory"
            ],
            "url": "https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/"
          },
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "tags": [
              "US Government Resource"
            ],
            "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20230"
          }
        ],
        "sourceIdentifier": "psirt@cisco.com",
        "vulnStatus": "Analyzed",
        "weaknesses": [
          {
            "description": [
              {
                "lang": "en",
                "value": "CWE-918"
              }
            ],
            "source": "psirt@cisco.com",
            "type": "Secondary"
          }
        ]
      }
    },
    "vulnrichment": {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-20230",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-25T19:50:08.910362Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-03T17:36:57.584Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/"
              },
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20230"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Unified Communications Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14"
                },
                {
                  "status": "affected",
                  "version": "14SU1"
                },
                {
                  "status": "affected",
                  "version": "14SU2"
                },
                {
                  "status": "affected",
                  "version": "14SU3"
                },
                {
                  "status": "affected",
                  "version": "15"
                },
                {
                  "status": "affected",
                  "version": "15SU1"
                },
                {
                  "status": "affected",
                  "version": "14SU4"
                },
                {
                  "status": "affected",
                  "version": "14SU4a"
                },
                {
                  "status": "affected",
                  "version": "15SU1a"
                },
                {
                  "status": "affected",
                  "version": "15SU2"
                },
                {
                  "status": "affected",
                  "version": "15.0.1.13010-1"
                },
                {
                  "status": "affected",
                  "version": "15.0.1.13011-1"
                },
                {
                  "status": "affected",
                  "version": "15.0.1.13012-1"
                },
                {
                  "status": "affected",
                  "version": "15.0.1.13013-1"
                },
                {
                  "status": "affected",
                  "version": "15.0.1.13014-1"
                },
                {
                  "status": "affected",
                  "version": "15.0.1.13015-1"
                },
                {
                  "status": "affected",
                  "version": "15.0.1.13016-1"
                },
                {
                  "status": "affected",
                  "version": "15.0.1.13017-1"
                },
                {
                  "status": "affected",
                  "version": "15SU3a"
                },
                {
                  "status": "affected",
                  "version": "14SU5"
                },
                {
                  "status": "affected",
                  "version": "15SU4"
                },
                {
                  "status": "affected",
                  "version": "15SU4a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.\r\n\r\nThis vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.\r\nNote: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.\r\nNote: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerability that is described in this advisory.\r\n\r\nIn June 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco continues to strongly recommend that customers upgrade to a fixed software release to remediate this vulnerability."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-01T16:28:16.838Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-cucm-ssrf-cXPnHcW",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW"
            }
          ],
          "source": {
            "advisory": "cisco-sa-cucm-ssrf-cXPnHcW",
            "defects": [
              "CSCws67331"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-20230",
        "datePublished": "2026-06-03T16:09:45.961Z",
        "dateReserved": "2025-10-08T11:59:15.399Z",
        "dateUpdated": "2026-07-01T16:28:16.838Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…