CVE-2026-20078
published 2026-04-15CVE-2026-20078: Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To…
PriorityP346medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.39%
30.9th percentile
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials.
These vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from an affected system.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | cisco_unity_connection | — | — |
| cisco | unity_connection | <= 12.5 | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_cisco3.1
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco Unity Connection up to 15SU3 HTTPS path traversal (cisco-sa-unity-file-download-RmKEVWPx / EUVD-2026-22956)
vuldb·2026-04-15·CVSS 6.5
CVE-2026-20078 [MEDIUM] Cisco Unity Connection up to 15SU3 HTTPS path traversal (cisco-sa-unity-file-download-RmKEVWPx / EUVD-2026-22956)
A vulnerability was found in Cisco Unity Connection. It has been declared as problematic. The affected element is an unknown function of the component HTTPS Handler. Executing a manipulation can lead to relative path traversal.
This vulnerability appears as CVE-2026-20078. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
GHSA-q6x9-g748-283m: Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system
ghsa_unreviewed·2026-04-15
CVE-2026-20078 [MEDIUM] CWE-23 GHSA-q6x9-g748-283m: Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials.
These vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from an affected system.
Cisco
Cisco Unity Connection Arbitrary File Download Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2026-20078 Cisco Unity Connection Arbitrary File Download Vulnerabilities
CVE-2026-20078: Cisco Unity Connection Arbitrary File Download Vulnerabilities
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials. These vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from an affected system. Cisco has released software updates that address these vulnerabilities. There are no
CVSS: 3.1
CWE: CWE-23, CWE-23
Bug IDs: CSCwq36816, CSCwr87730
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-15
Published