CVE-2026-20230: Cisco Unified CM WebDialer SSRF Can Lead to Root-Level Compromise
ID: 161f27d7-6390-5142-ab9b-da56de3b7b58
STIX ID: report--161f27d7-6390-5142-ab9b-da56de3b7b58
Feed Name: SOCRadar Blog
Cisco disclosed CVE-2026-20230, an unauthenticated SSRF in Cisco Unified CM and Unified CM SME (CVSS 8.6) that can be chained to write files to the appliance OS and potentially enable root-level compromise; exploitation requires the WebDialer service to be enabled (disabled by default). Cisco provides fixes and interim mitigations (disable WebDialer), PSIRT notes public PoC exists though no active exploitation has been observed, and defenders are advised to patch, disable WebDialer if necessary, and monitor for SSRF and post-exploitation indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
