CVE-2026-20230
Cisco Cisco Unified Communications Manager, unified communications manager
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elev...
- CVSS
- 8.6
- EPSS
- 83.2% 99.6% percentile
- CISA KEV
- Listed
- Published
- 2026.06.04