
- Home
- Threat Advisories
- NCSC-TAD-2606-004
NCSC-TAD-2606-004
Severity Level: High
Vulnerability
Reference No.: NCSC-TAD-2606-004CVSS 0
Critical SSRF Vulnerability in Cisco Unified Communications Manager
- Threat Type:
- N/A
- TLP:
- CLEAR
- CVE:
- CVE-2026-20230
Overview
This is a critical Server-Side Request Forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager products. An unauthenticated attacker can exploit this flaw by sending specially crafted HTTP requests to a vulnerable system with the WebDialer service enabled. Successful exploitation could allow the attacker to create files on the underlying operating system, potentially leading to privilege escalation and root-level access.
Affected Technologies
- Cisco Unified CM and Unified CM SME systems running with the WebDialer service enabled.
Mitigation and Immediate Actions
- 01
Apply the latest security updates.

