PT-2026-37649 · Cisco · Unity Connection Web Inbox

Published

2026-05-06

·

Updated

2026-05-06

·

CVE-2026-20035

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unity Connection Web Inbox (affected versions not specified)
Description Improper input validation for specific HTTP requests in the web UI allows an unauthenticated remote attacker to perform Server-Side Request Forgery (SSRF), a technique where the attacker forces the server to make requests to an unintended location. By sending a crafted HTTP request, an attacker can trigger arbitrary network requests originating from the affected device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-20035

Affected Products

Unity Connection Web Inbox