CVE-2026-20060
published 2026-04-15CVE-2026-20060: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a…
PriorityP426medium4.7CVSS 3.1
AVNACLPRNUIRSCCNILAN
EPSS
0.20%
10.4th percentile
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.
This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious web page.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | unity_connection | <= 12.5 | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
vendor_cisco3.1
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wxm9-c4v7-5x34: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to
ghsa_unreviewed·2026-04-15
CVE-2026-20060 [MEDIUM] CWE-601 GHSA-wxm9-c4v7-5x34: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.
This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious web page.
VulDB
Cisco Unity Connection up to 15SU3 Web-based Management Interface Request redirect (cisco-sa-unity-vulns-n2EJSbbw / EUVD-2026-22953)
vuldb·2026-04-15·CVSS 4.7
CVE-2026-20060 [MEDIUM] Cisco Unity Connection up to 15SU3 Web-based Management Interface Request redirect (cisco-sa-unity-vulns-n2EJSbbw / EUVD-2026-22953)
A vulnerability was found in Cisco Unity Connection up to 15SU3 and classified as problematic. This issue affects some unknown processing of the component Web-based Management Interface. Such manipulation of the argument Request leads to open redirect.
This vulnerability is documented as CVE-2026-20060. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
Cisco
Cisco Unity Connection Cross-Site Scripting, Open Redirect, and SQL Injection Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2026-20060 Cisco Unity Connection Cross-Site Scripting, Open Redirect, and SQL Injection Vulnerabilities
CVE-2026-20060: Cisco Unity Connection Cross-Site Scripting, Open Redirect, and SQL Injection Vulnerabilities
Multiple vulnerabilities in Cisco Unity Connection could allow a remote attacker to conduct a cross-site scripting (XSS) attack, an open redirect attack, and an SQL injection attack. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-601, CWE-79, CWE-89, CWE-601, CWE-79, CWE-89
Bug IDs: CSCwq36796, CSCwq36822, CSCwq36828, CSCwq36822, CSCwq36828
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-15
Published