logo

Cisco Unified Communications Manager Flaw Exposes Systems to SSRF Attacks and Root Access

ID: f8cd0fd6-9789-5a67-aeb6-aea94549bcd7

STIX ID: report--f8cd0fd6-9789-5a67-aeb6-aea94549bcd7

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Divya

...
...

Cisco disclosed a critical server-side request forgery (SSRF) vulnerability (CVE-2026-20230) in Unified Communications Manager and Unified CM SME that can allow unauthenticated attackers to write files to the underlying OS and escalate to root when the Cisco WebDialer service is enabled; Cisco assigned a CVSS v3.1 base score of 8.6, released fixes for 14SU6 with patches for 15 planned or available via interim COPs, recommends disabling WebDialer as a temporary mitigation, and notes a proof-of-concept exists though no active exploitation has been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.