Cisco patches SSRF flaw in Unified CM enabling root access
vulnerabilityopenJun 4, 2026 — Jun 5, 2026
CVE-2026-20230 is a critical unauthenticated SSRF vulnerability affecting Cisco Unified CM and SME. This flaw can lead to root-level compromise when the WebDialer service is enabled, which is disabled by default. Exploitation involves sending a crafted HTTP request that manipulates the server, allowing the attacker to write files and potentially elevate…
Root sourcesec.cloudapps.cisco.com
Timeline Coverage
Swipe to explore timeline
-
Cisco patches SSRF flaw in Unified CM enabling root access
socradar.io
-
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
thehackernews.com
-
Cisco Fixes CVE-2026-20230 SSRF Flaw in Unified CM, Root Risk.
securityaffairs.com
-
Cisco patches CVE-2026-20230 UC Manager flaw enabling root access
www.securityweek.com
-
Cisco Unified CM SSRF flaw exposes systems to remote takeover
securityonline.info