Vulnerability record · CVE-2026-20230 · published 3 June 2026
CVE-2026-20230: Cisco Unified CM SSRF enables file write and root escalation
Cisco · Unified Communications Manager
Cisco Unified Communications Manager and Unified CM SME fail to properly validate input for specific HTTP requests, allowing server-side request forgery. A successful attack lets an unauthenticated remote attacker write files to the underlying operating system, which can later be used to elevate privileges to root. Cisco rates the advisory Critical despite the 8.6 CVSS score because of the root escalation outcome.
Description
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Automated analysis
critical priorityCISA KEV listing with a near-term due date, very high EPSS, public exploit reference, and unauthenticated network reachability leading to root make this a top remediation priority.
What it is
Cisco Unified Communications Manager and Unified CM SME fail to properly validate input for specific HTTP requests, allowing server-side request forgery. A successful attack lets an unauthenticated remote attacker write files to the underlying operating system, which can later be used to elevate privileges to root. Cisco rates the advisory Critical despite the 8.6 CVSS score because of the root escalation outcome.
Impact
An attacker gains the ability to write arbitrary files on the appliance and, by chaining that write, escalate to root on the Unified CM host. That level of access compromises the call-control platform and anything it trusts.
Attack surface
The flaw is reachable over the network via a crafted HTTP request with no authentication and no user interaction (CVSS AV:N/PR:N/UI:N). Exploitation requires the WebDialer service to be enabled; it is disabled by default, which narrows exposure to deployments that turned it on.
Exploitation
CVE-2026-20230 is listed in CISA KEV with a 2026-06-28 remediation due date, and a third-party reference is tagged as an exploit, indicating public exploitation. EPSS is 0.882 (99.76th percentile), so exploitation is expected to be widespread.
What to do
- Apply the Cisco vendor advisory patch for Unified CM and Unified CM SME as the first action.
- If patching cannot be done immediately, disable the WebDialer service, which is off by default and is required for exploitation.
- Follow CISA BOD 26-04 guidance and the KEV required action, including the 2026-06-28 due date.
- Restrict network access to Unified CM management and web interfaces so only trusted administrative networks can reach them.
- If mitigations are unavailable, evaluate discontinuing use of the affected product per CISA guidance.
Detection
- Review Unified CM and WebDialer HTTP logs for crafted or anomalous requests that trigger outbound connections or unexpected server-side fetches.
- Monitor the filesystem for new or modified files in web-accessible or service directories on Unified CM hosts.
- Alert on unexpected privilege escalation or root-level process activity on Unified CM appliances.
- Hunt for WebDialer service being enabled on hosts where it should be disabled.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-20230 to the Known Exploited Vulnerabilities catalog on 25 June 2026 as "Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 28 June 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW | Vendor Advisory |
| https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20230 | US Government Resource |
Track CVE-2026-20230 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-20230), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.