{"id":"CVE-2026-20034","title":"A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device.\r\n\r\nThis vulnerability is due to insufficient validation of use…","summary":"A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device.\r\n\r\nThis vulnerability is due to insufficient validation of use…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-35"],"vendor":"cisco","product":"unity_connection","affected":["unity_connection < 14.0","unity_connection = 14.0","unity_connection = 14su1","unity_connection = 14su2","unity_connection = 14su3","unity_connection = 14su4","unity_connection = 15.0","unity_connection = 15su1","unity_connection = 15su2","unity_connection = 15su3"],"patched":["unity_connection 14.0"],"published":"2026-05-06","updated":"2026-07-01","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20034","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-rce-ssrf-hENhuASy","label":"psirt@cisco.com"}],"tags":["nvd"],"epss":0.00712,"epssPercentile":0.5175,"ingestedAt":"2026-07-01T16:42:14.743Z","slug":"CVE-2026-20034","body":"## Overview\n\nA vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of a targeted device.&nbsp;To exploit this vulnerability, the attacker must have valid user credentials on the affected device.\n\n## Affected\n\n- `unity_connection < 14.0`\n- `unity_connection = 14.0`\n- `unity_connection = 14su1`\n- `unity_connection = 14su2`\n- `unity_connection = 14su3`\n- `unity_connection = 14su4`\n- `unity_connection = 15.0`\n- `unity_connection = 15su1`\n- `unity_connection = 15su2`\n- `unity_connection = 15su3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `unity_connection 14.0`","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}