← Vulnerability feed

Vulnerability record · CVE-2026-20230 · published 3 June 2026

CVE-2026-20230: Cisco Unified CM SSRF enables file write and root escalation

Cisco · Unified Communications Manager

Cisco Unified Communications Manager and Unified CM SME fail to properly validate input for specific HTTP requests, allowing server-side request forgery. A successful attack lets an unauthenticated remote attacker write files to the underlying operating system, which can later be used to elevate privileges to root. Cisco rates the advisory Critical despite the 8.6 CVSS score because of the root escalation outcome.

8.6 CVSS 3.1 High CISA KEV since 25 Jun 2026 EPSS 88% · top 0.2% CWE-918 · Server-side request forgery (SSRF)
8.6CVSS 3.1 base score
88%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 1 tagged exploit
22 Jul 2026Last modified by NVD

Description

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCISA KEV listing with a near-term due date, very high EPSS, public exploit reference, and unauthenticated network reachability leading to root make this a top remediation priority.

What it is

Cisco Unified Communications Manager and Unified CM SME fail to properly validate input for specific HTTP requests, allowing server-side request forgery. A successful attack lets an unauthenticated remote attacker write files to the underlying operating system, which can later be used to elevate privileges to root. Cisco rates the advisory Critical despite the 8.6 CVSS score because of the root escalation outcome.

Impact

An attacker gains the ability to write arbitrary files on the appliance and, by chaining that write, escalate to root on the Unified CM host. That level of access compromises the call-control platform and anything it trusts.

Attack surface

The flaw is reachable over the network via a crafted HTTP request with no authentication and no user interaction (CVSS AV:N/PR:N/UI:N). Exploitation requires the WebDialer service to be enabled; it is disabled by default, which narrows exposure to deployments that turned it on.

Exploitation

CVE-2026-20230 is listed in CISA KEV with a 2026-06-28 remediation due date, and a third-party reference is tagged as an exploit, indicating public exploitation. EPSS is 0.882 (99.76th percentile), so exploitation is expected to be widespread.

What to do

  • Apply the Cisco vendor advisory patch for Unified CM and Unified CM SME as the first action.
  • If patching cannot be done immediately, disable the WebDialer service, which is off by default and is required for exploitation.
  • Follow CISA BOD 26-04 guidance and the KEV required action, including the 2026-06-28 due date.
  • Restrict network access to Unified CM management and web interfaces so only trusted administrative networks can reach them.
  • If mitigations are unavailable, evaluate discontinuing use of the affected product per CISA guidance.

Detection

  • Review Unified CM and WebDialer HTTP logs for crafted or anomalous requests that trigger outbound connections or unexpected server-side fetches.
  • Monitor the filesystem for new or modified files in web-accessible or service directories on Unified CM hosts.
  • Alert on unexpected privilege escalation or root-level process activity on Unified CM appliances.
  • Hunt for WebDialer service being enabled on hosts where it should be disabled.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-20230 to the Known Exploited Vulnerabilities catalog on 25 June 2026 as "Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 28 June 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-20230 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-20045Cisco Unified Communications products HTTP input code injection RCECisco Unified CM, Unified CM SME, IM & Presence, Unity Connection, and Webex Calling Dedicated Instance fail to properly validate user-supplied input…KEVEPSS 4.5%analysed10.0CVE-2025-20309Cisco unified communications manager hard-coded credentials vulnerabilityA vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM …EPSS 1.1%10.0CVE-2024-20253Cisco unified communications manager deserialization of untrusted data vulnerabilityA vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to exe…EPSS 2.4%10.0CVE-2011-1643Cisco unified communications manager information exposure vulnerabilityCisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x, 7.x before 7.1(5b)su4, 8.0, and 8.5 before 8.5(1)su2 and Cisco Unified Pre…EPSS 1.9%10.0CVE-2008-1154Cisco emergency responder improper authentication vulnerabilityThe Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and…EPSS 5.1%10.0CVE-2008-0027Cisco Unified Communications Manager CTL Provider heap buffer overflowThe Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager and CallManager contains a heap-based buf…EPSS 57%analysed10.0CVE-2007-5538Cisco unified callmanager memory buffer overflow vulnerabilityBuffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(3), …EPSS 5.5%

Source: NIST National Vulnerability Database (record CVE-2026-20230), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.