logo

CVE-2026-20230: Cisco Unified CM WebDialer SSRF Can Lead to Root-Level Compromise

ID: 161f27d7-6390-5142-ab9b-da56de3b7b58

STIX ID: report--161f27d7-6390-5142-ab9b-da56de3b7b58

Feed Name: SOCRadar Blog

Threat Score
70/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Ameer Owda

...
...

Cisco disclosed CVE-2026-20230, an unauthenticated SSRF in Cisco Unified CM and Unified CM SME (CVSS 8.6) that can be chained to write files to the appliance OS and potentially enable root-level compromise; exploitation requires the WebDialer service to be enabled (disabled by default). Cisco provides fixes and interim mitigations (disable WebDialer), PSIRT notes public PoC exists though no active exploitation has been observed, and defenders are advised to patch, disable WebDialer if necessary, and monitor for SSRF and post-exploitation indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.