Path traversal in Cisco Unity Connection - CVE-2026-20034
Published: May 7, 2026
Cisco Unity Connection
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the web-based management interface. A remote user can send a specially crafted API request and upload arbitrary files on the system, leading to arbitrary code execution.