Skip to main content
عربي
logo

NCSC-TAD-2606-004

Severity Level: High
Vulnerability

Reference No.: NCSC-TAD-2606-004CVSS 0

Critical SSRF Vulnerability in Cisco Unified Communications Manager

Threat Type:
N/A
TLP:
CLEAR
CVE:
CVE-2026-20230

Overview

This is a critical Server-Side Request Forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager products. An unauthenticated attacker can exploit this flaw by sending specially crafted HTTP requests to a vulnerable system with the WebDialer service enabled. Successful exploitation could allow the attacker to create files on the underlying operating system, potentially leading to privilege escalation and root-level access.

Affected Technologies

  • Cisco Unified CM and Unified CM SME systems running with the WebDialer service enabled.

Mitigation and Immediate Actions

  1. 01

    Apply the latest security updates.

References