Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-20230 |
| Alert Source | Cisco Security Advisory (public PoC available) |
| CVE Publication Year | 2026 |
| Date Published | 2026-06-04 |
| Vendor | Cisco |
| Product | Unified Communications Manager (CUCM) |
| CVSS Score | 8.6 (high) |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
A public Proof of Concept (PoC) has been released for CVE-2026-20230, a previously patched vulnerability affecting Cisco Unified Communications Manager (CUCM) and Cisco Unified CM Session Management Edition (CUCM SME). The flaw stems from insufficient input validation in the WebDialer component and can be exploited remotely through specially crafted HTTP requests.
According to Cisco, successful exploitation may allow an attacker to perform Server-Side Request Forgery (SSRF) — accessing internal resources — and arbitrary file writes on the filesystem of vulnerable systems, leading to potential system compromise. The public availability of a PoC significantly increases the likelihood of exploitation attempts by threat actors.
Affected products and versions:
- Cisco Unified Communications Manager (CUCM) — version 14 prior to 14SU6; version 15 prior to 15SU5
- Cisco Unified CM Session Management Edition (CUCM SME) — version 14 prior to 14SU6; version 15 prior to 15SU5
Required Actions
Update Cisco Unified Communications Manager and Unified CM Session Management Edition promptly to the vendor-fixed versions (14SU6 / 15SU5 or later). Restrict network access to the administrative and WebDialer interfaces and monitor for anomalous HTTP requests given the public PoC.
Who Is Affected?
This vulnerability affects Unified Communications Manager (CUCM) by Cisco. Check if your organization runs an affected CUCM or CUCM SME version (14 < 14SU6, 15 < 15SU5) and apply the vendor-fixed release.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
