Server-Side Request Forgery (SSRF) in Cisco Unified Communications Manager Session Management Edition and Cisco Unified Communications Manager - CVE-2026-20230

 

Server-Side Request Forgery (SSRF) in Cisco Unified Communications Manager Session Management Edition and Cisco Unified Communications Manager - CVE-2026-20230

Published: June 4, 2026 / Updated: June 24, 2026


Vulnerability identifier: #VU133306
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:H/SI:H/SA:N]
CVE-ID: CVE-2026-20230
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to write files to the underlying operating system.

The vulnerability exists due to server-side request forgery in the WebDialer service when handling crafted HTTP requests. A remote attacker can send a crafted HTTP request to write files to the underlying operating system.

Only instances with the WebDialer service enabled are vulnerable. The written files could be used later to elevate privileges to root.


Affected software

Cisco Unified Communications Manager Session Management Edition
Cisco Unified Communications Manager

How to mitigate CVE-2026-20230

Install security update from vendor's website.

Cisco Unified Communications Manager Session Management Edition - update to 14SU6
Cisco Unified Communications Manager - update to 14SU6

External References

Related Security Bulletins