---
id: CVE-2026-20034
title: "A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device.\r\n\r\nThis vulnerability is due to insufficient validation of use…"
summary: "A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device.\r\n\r\nThis vulnerability is due to insufficient validation of use…"
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-35
vendor: cisco
product: unity_connection
affected:
  - unity_connection < 14.0
  - unity_connection = 14.0
  - unity_connection = 14su1
  - unity_connection = 14su2
  - unity_connection = 14su3
  - unity_connection = 14su4
  - unity_connection = 15.0
  - unity_connection = 15su1
  - unity_connection = 15su2
  - unity_connection = 15su3
patched:
  - unity_connection 14.0
published: '2026-05-06'
updated: '2026-07-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20034'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-rce-ssrf-hENhuASy
    label: psirt@cisco.com
tags:
  - nvd
epss: 0.00712
epssPercentile: 0.51604
ingestedAt: '2026-07-01T16:42:14.743Z'
---

## Overview

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of a targeted device.&nbsp;To exploit this vulnerability, the attacker must have valid user credentials on the affected device.

## Affected

- `unity_connection < 14.0`
- `unity_connection = 14.0`
- `unity_connection = 14su1`
- `unity_connection = 14su2`
- `unity_connection = 14su3`
- `unity_connection = 14su4`
- `unity_connection = 15.0`
- `unity_connection = 15su1`
- `unity_connection = 15su2`
- `unity_connection = 15su3`

## Remediation

Upgrade past the affected range:

- `unity_connection 14.0`
