CISCO Security Advisory
Published Date: July 1, 2026
CVE: CVE-2026-20230
Advisory Summary
🔐 ⚠️ Critical Server-Side Request Forgery Vulnerability in Cisco Unified Communications Manager ⚠️ 🔐
A critical security flaw (CVE-2026-20230) has been identified in Cisco Unified Communications Manager (Unified CM) and its Session Management Edition (SME). This vulnerability arises from improper input validation of specific HTTP requests, enabling unauthenticated remote attackers to perform server-side request forgery (SSRF) attacks.
- Attackers can send crafted HTTP requests to the affected device.
- Successful exploitation allows writing files to the underlying operating system, potentially escalating privileges to root.
- This severity is underscored by Cisco’s assignment of a Critical Security Impact Rating due to the root privilege escalation risk.
- Notably, exploitation requires the WebDialer service to be enabled, which is disabled by default, somewhat limiting exposure.
- Cisco has released software updates to remediate this vulnerability—applying these immediately is essential as no workaround exists.
- Organizations using Cisco Unified CM or SME should verify their WebDialer service status and prioritize patch deployment.
- Proactive monitoring for unusual HTTP request patterns targeting Unified CM devices is advisable.
This vulnerability poses a significant risk to communication infrastructure, potentially allowing attackers to gain full control over affected systems. Network security teams should treat this update with the highest priority to prevent possible breaches.
-20230
Reference: Vendor Advisory