Server-Side Request Forgery (SSRF) in Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise - CVE-2026-20314
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to conduct server-side request forgery attacks.
The vulnerability exists due to improper input validation in specific HTTP requests when handling crafted HTTP requests. A remote user can send a crafted HTTP request to conduct server-side request forgery attacks.
A successful exploit could allow arbitrary network requests to be sent from the affected device.
Affected software
Cisco Unified Contact Center Enterprise
How to mitigate CVE-2026-20314
Cisco Unified Contact Center Enterprise - update to 15.0(1)ES202607