cbcvebase.
CVE-2026-20230
published 2026-06-03

CVE-2026-20230: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could…

PriorityP191high8.6CVSS 3.1
AVNACLPRNUINSCCNIHAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-06-28
Exploited in the wild
EPSS
80.88%
99.6th percentile
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.

Affected

24 ranges
VendorProductVersion rangeFixed in
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscounified_communications_manager>= 14.0 < 14su614su6
ciscounified_communications_manager15.0 – 15su4a

Detection & IOCsextracted from sources · hover to see the quote

path/tmp/cve-2026-20230-test.txt
otherfile:// URI scheme used as SSRF payload for arbitrary file-write
  • Detect crafted HTTP requests targeting the Cisco Unified CM WebDialer component containing file:// URI schemes, which are used to trigger the SSRF file-write primitive.
  • Monitor for creation of unexpected files under /tmp/ on Cisco Unified CM hosts, particularly files matching the pattern /tmp/cve-2026-20230-test.txt, as reconnaissance-phase exploitation attempts write text files to this path.
  • Alert on exploitation attempts originating from a single source IP conducting repeated HTTP requests with file:// payloads against Cisco Unified CM endpoints; current observed campaign uses a single source IP.
  • Check whether the Cisco WebDialer Web Service status is 'Started' in the CTI Services section of Control Center - Feature Services; exploitation requires WebDialer to be enabled.
  • Monitor for attacker pre-exploitation hostname enumeration activity against the Webdialer component, as exploitation requires the attacker to first obtain the target system's hostname before carrying out the file-write attack.
  • Watch for webshell drops following file-write exploitation of CVE-2026-20230; post-reconnaissance exploitation is expected to escalate to webshell deployment and root privilege escalation.
  • ·Exploitation of CVE-2026-20230 requires the WebDialer service to be enabled on the target Cisco Unified CM instance; WebDialer is disabled by default, significantly limiting the attack surface.
  • ·Patched versions are Cisco Unified CM and Unified CM SME 14SU6 and 15SU5; if patching is not immediately possible, disabling the WebDialer service is the recommended interim mitigation.

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
vulncheck8.6HIGH
cisa8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.