Knox CVE Database
/
CVE-2026-20230
High
8.6

CVE-2026-20230: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

Added to the CISA KEV catalog:
June 25, 2026

Overview

Cisco Unified Communications Manager contains a server-side request forgery flaw in its WebDialer service that allows an unauthenticated remote attacker to write arbitrary files to the underlying operating system. Those written files can then be used to escalate privileges to root. Cisco rates this advisory Critical, noting the score understates the risk because full root compromise is the realistic outcome. Affected versions span the 14 and 15 release lines; exploitation requires the WebDialer service to be enabled, which it is not by default.

Vulnerability details

Affected vendor
Cisco
Affected product
Unified Communications Manager
Weakness type (CWE)
CWE-918

The WebDialer component in Unified CM processes inbound HTTP requests to handle click-to-call integrations. Because it fails to validate attacker-supplied URL and URI parameters against an allowlist, it can be forced to initiate internal connections on behalf of an external caller, a textbook CWE-918 (Server-Side Request Forgery) condition. The server-side application acts as an unintended internal proxy, routing attacker-controlled inputs to privileged local services that would otherwise be unreachable from an external network position. No authentication, session token, or prior account access is required to reach the vulnerable endpoint.


An attacker with network access to the WebDialer web interface sends a crafted HTTP request containing malformed URI parameters or loopback indicators. The WebDialer service processes the request without validation and initiates internal connections on the attacker's behalf, ultimately writing attacker-influenced content to the host filesystem. Those written files can subsequently be used to escalate privileges to root on the Unified CM host. The precondition is that WebDialer must be in a Started state; because it is disabled by default, only deployments where the service has been explicitly activated are exposed. Cisco PSIRT confirmed active exploitation in June 2026, and proof-of-concept code is publicly available.

Severity and impact

8.6
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality impact
None
Integrity impact
High
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Check the Cisco Unified Serviceability Control Center under CTI Services: if the Cisco WebDialer Web Service shows status 'Started' on an internet-facing or untrusted-network-accessible node, the system is exposed and should be treated as a priority for patching or service disablement.
  • Review web server access logs on Unified CM nodes for HTTP requests to WebDialer endpoints originating from sources outside the expected internal telephony client population, particularly requests containing loopback addresses, internal RFC-1918 destinations, or unusual URI structures in parameters that should carry only extension or user data.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
June 28, 2026

Additional hardening

  • Upgrade Unified CM and Unified CM SME release 14 to 14SU6, and release 15 to 15SU5 or the available COP patch; consult the vendor advisory listed in References for patch-specific README instructions before applying.
  • If immediate patching is not possible, disable the Cisco WebDialer Web Service via Cisco Unified Serviceability under Service Activation in the CTI Services section; Cisco confirms this prevents exploitation while the patch is pending.
  • Restrict network access to Unified CM administrative and WebDialer interfaces to trusted internal telephony subnets only; internet-facing exposure of these endpoints removes the network-access precondition and dramatically widens the attacker pool.
  • Audit all Unified CM nodes to confirm whether WebDialer is enabled; because it is off by default, any node showing it as Started warrants immediate review of whether that activation was intentional and authorized.

Key dates

Published (NVD)
June 3, 2026
Added to CISA KEV
June 25, 2026
Remediation deadline
June 28, 2026
Last updated
July 22, 2026

References

Frequently asked questions

Does CVE-2026-20230 affect my FedRAMP authorization?

If Cisco Unified Communications Manager runs inside your authorization boundary, CVE-2026-20230 affects your FedRAMP authorization directly. CISA has listed this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of June 28, 2026. An unpatched KEV within your boundary is an assessor finding. You must either remediate it before that date or formally document a mitigation, or your sponsoring agency will raise it.

How does Knox help me handle CVE-2026-20230?

Knox does not patch Cisco Unified Communications Manager on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2026-20230 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work is yours to execute; you do not manage the compliance posture around it alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-20230. Because monitoring runs continuously, exposure surfaces during ongoing review rather than only when an assessor arrives. That earlier signal gives your team time to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-20230 isn't remediated by June 28, 2026?

If CVE-2026-20230 is not remediated by June 28, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization in good standing and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting