CVE-2026-20061
published 2026-04-15CVE-2026-20061: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection…
PriorityP343medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.23%
13.8th percentile
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP(S) request to the web-based management interface of an affected device. A successful exploit could allow the attacker to view data on the affected device.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | unity_connection | <= 12.5 | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_cisco3.1
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unity Connection Cross-Site Scripting, Open Redirect, and SQL Injection Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2026-20061 Cisco Unity Connection Cross-Site Scripting, Open Redirect, and SQL Injection Vulnerabilities
CVE-2026-20061: Cisco Unity Connection Cross-Site Scripting, Open Redirect, and SQL Injection Vulnerabilities
Multiple vulnerabilities in Cisco Unity Connection could allow a remote attacker to conduct a cross-site scripting (XSS) attack, an open redirect attack, and an SQL injection attack. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-601, CWE-79, CWE-89, CWE-601, CWE-79, CWE-89
Bug IDs: CSCwq36796, CSCwq36822, CSCwq36828, CSCwq36822, CSCwq36828
GHSA
GHSA-3w73-fhv4-qr7q: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL inject
ghsa_unreviewed·2026-04-15
CVE-2026-20061 [MEDIUM] CWE-89 GHSA-3w73-fhv4-qr7q: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL inject
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP(S) request to the web-based management interface of an affected device. A successful exploit could allow the attacker to view data on the affected device.
VulDB
Cisco Unity Connection up to 15SU3 Web-based Management Interface sql injection (cisco-sa-unity-vulns-n2EJSbbw / EUVD-2026-22955)
vuldb·2026-04-15·CVSS 4.3
CVE-2026-20061 [MEDIUM] Cisco Unity Connection up to 15SU3 Web-based Management Interface sql injection (cisco-sa-unity-vulns-n2EJSbbw / EUVD-2026-22955)
A vulnerability was found in Cisco Unity Connection up to 15SU3. It has been classified as critical. Impacted is an unknown function of the component Web-based Management Interface. Performing a manipulation results in sql injection.
This vulnerability is reported as CVE-2026-20061. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-15
Published