CISCO Security Advisory
Published Date: Not specified
CVE: CVE-2026-20314
Advisory Summary
🗓️ Published Date: 19 Aug 2026
📌 TITLE: Cisco Contact Center SSRF—Authenticated Remote Risk in Packaged CCE / Unified CCE
⚠️ ALARM: Server-Side Request Forgery (SSRF) via crafted HTTP
Cisco reports a vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) that could let an authenticated, remote attacker trigger SSRF. The attacker can coerce the affected server into making arbitrary outbound network requests, effectively using the contact center platform as a “proxy” for internal or external targeting.
- Root cause is improper input validation for specific HTTP requests.
- Exploitation requires valid user credentials on the affected device.
- Successful exploitation enables network calls sourced from the device, which can broaden impact (e.g., reaching internal endpoints, metadata services, or other reachable systems), depending on environment controls.
- Cisco has released software updates to address the issue.
- No workarounds are provided, meaning operationally the safest path is timely upgrade/patching.
🔐 ACTIONABLE: What market professionals should do now
1. Identify affected deployments of Packaged CCE / Unified CCE and inventory current versions.
2. Prioritize patching per Cisco guidance (plan change windows—contact center platforms often require coordinated service cutovers).
3. Harden network egress from the contact center servers (restrict outbound destinations wherever possible).
4. Review authentication exposure: ensure admin and application endpoints are protected (MFA, strong credential policies, least-privilege, and tighter access lists).
5. Monitor for SSRF indicators: unusual outbound requests from the contact center app layer, new destinations, or denied internal traffic patterns.
- CVE: CVE-2026-20314
- Security impact rating: Medium
- Vulnerability class: SSRF (server-side request forgery)
-2026-20314
Reference: Vendor Advisory