PT-2026-45987 · Cisco · Cisco Unified Communications Manager Session Management Edition+1
CVE-2026-20230
·
Published
2026-06-03
·
Updated
2026-07-17
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Unified Communications Manager versions prior to 14SU6
Cisco Unified Communications Manager versions prior to 15SU5
Cisco Unified Communications Manager Session Management Edition (affected versions not specified)
Description
An unauthenticated remote attacker can conduct server-side request forgery (SSRF) attacks through an affected device due to improper input validation for specific HTTP requests. This issue specifically affects the WebDialer service, which must be enabled for exploitation to occur. A successful attack allows the adversary to write arbitrary files to the underlying operating system, which can be used to drop webshells, achieve remote code execution, and elevate privileges to root. Real-world exploitation has been confirmed, with attackers using
file:// payloads to create files on target devices. Approximately 5,000 instances have been identified globally, with over 200 confirmed as being exposed to the internet.Recommendations
Update Cisco Unified Communications Manager to version 14SU6.
Update Cisco Unified Communications Manager to version 15SU5.
As a temporary workaround, disable the WebDialer service to minimize the risk of exploitation.
Exploit
Fix
LPE
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Unified Communications Manager
Cisco Unified Communications Manager Session Management Edition