{"id":"CVE-2026-20230","title":"A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forg…","summary":"A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forg…","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N","cwe":["CWE-918"],"vendor":"cisco","product":"unified_communications_manager","affected":["unified_communications_manager >= 14.0, < 14su6","unified_communications_manager >= 15.0, <= 15su4a"],"patched":["unified_communications_manager 14su6"],"published":"2026-06-03","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:17:37.003","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20230","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW","label":"psirt@cisco.com"},{"url":"https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20230","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available","cve.org"],"epss":0.882,"epssPercentile":0.99766,"kev":true,"kevDateAdded":"2026-06-25","kevDueDate":"2026-06-28","kevRansomware":false,"exploited":true,"exploits":{"github":3,"githubRepos":["https://github.com/HORKimhab/CVE-2026-20230","https://github.com/W5M1n9/Cisco-Unified-Communications-Manager-Server-Side-Forgery-Request-Vulnerability-CVE-2026-20230","https://github.com/HalilDeniz/CVE-2026-20230-Scanner"],"checkedAt":"2026-10-07T20:47:22.833Z"},"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"no","technicalImpact":"total","timestamp":"2026-06-26T03:55:20.543122Z"},"ingestedAt":"2026-10-07T18:42:20.905Z","slug":"CVE-2026-20230","body":"## Overview\n\nA vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.\r\n\r\nThis vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.\r\nNote: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.\r\nNote: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.\n\n## Affected\n\n- `unified_communications_manager >= 14.0, < 14su6`\n- `unified_communications_manager >= 15.0, <= 15su4a`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `unified_communications_manager 14su6`","depth":"abyssal","depthScore":90,"depthScoreParts":{"impact":47.3,"likelihood":17.6,"exploitation":25,"ransomware":0},"changes":[]}