---
id: CVE-2026-20230
title: >-
  A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco
  Unified Communications Manager Session Management Edition (Unified CM SME)
  could allow an unauthenticated, remote attacker to conduct server-side request
  forg…
summary: >-
  A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco
  Unified Communications Manager Session Management Edition (Unified CM SME)
  could allow an unauthenticated, remote attacker to conduct server-side request
  forg…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N'
cwe:
  - CWE-918
vendor: cisco
product: unified_communications_manager
affected:
  - 'unified_communications_manager >= 14.0, < 14su6'
  - 'unified_communications_manager >= 15.0, <= 15su4a'
patched:
  - unified_communications_manager 14su6
published: '2026-06-03'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:37.003'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20230'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW
    label: psirt@cisco.com
  - url: 'https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20230
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
  - cve.org
epss: 0.882
epssPercentile: 0.99766
kev: true
kevDateAdded: '2026-06-25'
kevDueDate: '2026-06-28'
kevRansomware: false
exploited: true
exploits:
  github: 3
  githubRepos:
    - 'https://github.com/HORKimhab/CVE-2026-20230'
    - >-
      https://github.com/W5M1n9/Cisco-Unified-Communications-Manager-Server-Side-Forgery-Request-Vulnerability-CVE-2026-20230
    - 'https://github.com/HalilDeniz/CVE-2026-20230-Scanner'
  checkedAt: '2026-10-07T20:47:22.833Z'
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-06-26T03:55:20.543122Z'
ingestedAt: '2026-10-07T18:42:20.905Z'
---

## Overview

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.

This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.
Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.
Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.

## Affected

- `unified_communications_manager >= 14.0, < 14su6`
- `unified_communications_manager >= 15.0, <= 15su4a`

## Remediation

Upgrade past the affected range:

- `unified_communications_manager 14su6`
