CVE-2026-20059
published 2026-04-15CVE-2026-20059: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS…
PriorityP430medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.19%
9.2th percentile
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface.
This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | unity_connection | <= 12.5 | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vendor_cisco3.1
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unity Connection Cross-Site Scripting, Open Redirect, and SQL Injection Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2026-20059 Cisco Unity Connection Cross-Site Scripting, Open Redirect, and SQL Injection Vulnerabilities
CVE-2026-20059: Cisco Unity Connection Cross-Site Scripting, Open Redirect, and SQL Injection Vulnerabilities
Multiple vulnerabilities in Cisco Unity Connection could allow a remote attacker to conduct a cross-site scripting (XSS) attack, an open redirect attack, and an SQL injection attack. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-601, CWE-79, CWE-89, CWE-601, CWE-79, CWE-89
Bug IDs: CSCwq36796, CSCwq36822, CSCwq36828, CSCwq36822, CSCwq36828
GHSA
GHSA-83qv-c52p-jx5j: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected
ghsa_unreviewed·2026-04-15
CVE-2026-20059 [MEDIUM] CWE-79 GHSA-83qv-c52p-jx5j: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface.
This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
VulDB
Cisco Unity Connection up to 15SU4 Web-based Management Interface cross site scripting (cisco-sa-unity-vulns-n2EJSbbw / EUVD-2026-22951)
vuldb·2026-04-15·CVSS 6.1
CVE-2026-20059 [MEDIUM] Cisco Unity Connection up to 15SU4 Web-based Management Interface cross site scripting (cisco-sa-unity-vulns-n2EJSbbw / EUVD-2026-22951)
A vulnerability marked as problematic has been reported in Cisco Unity Connection up to 15SU4. Affected by this vulnerability is an unknown functionality of the component Web-based Management Interface. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2026-20059. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-15
Published