
[CIVN-2026-0339] Privilege Escalation Vulnerability in Cisco Unified Communications Manager
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Privilege Escalation Vulnerability in Cisco Unified Communications Manager
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Cisco Unified Communications Manager and Cisco Unified Communications Manager SME Release 14 prior to 14SU6
Cisco Unified Communications Manager and Cisco Unified Communications Manager SME Release 15 prior to 15SU5 (Sep 2026) or COP
Note: Vulnerability is only exploitable on systems with WebDialer service enabled (disabled by default)
Overview
A vulnerability has been reported in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) that could allow an unauthenticated, remote attacker to conduct Server-Side Request Forgery (SSRF) attacks and potentially gain root-level privileges on the affected system.
Target Audience:
All IT administrators, network administrators, VoIP administrators, and individuals responsible for maintaining Cisco Unified Communications infrastructure.
Risk Assessment:
Critical risk of unauthenticated remote exploitation leading to privilege escalation.
Impact Assessment:
Potential for unauthorised root privilege access.
Description
Cisco Unified Communications Manager (Unified CM) is a centralized enterprise communications platform that provides call control and management for voice, video, messaging, mobility, and conferencing services.
The vulnerability exists due to improper input validation for specific HTTP requests in affected products. An attacker could exploit this vulnerability by sending a specially crafted HTTP request to an affected device.
Successful exploitation could allow an unauthenticated, remote attacker to conduct Server-Side Request Forgery (SSRF) attacks and potentially gain root-level privileges on the affected system.
Note: It has been reported that this vulnerability is actively being exploited.
Solution
Apply appropriate security updates/workarounds as mentioned in the Cisco advisory:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW
Vendor Information
Cisco
https://sec.cloudapps.cisco.com/security/center/publicationListing.x
References
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW
CVE Name
CVE-2026-20230
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmo78pkACgkQ3jCgcSdc
ys/jRw/+OEKbBSdCII+ZIHrI4lnXrGSj5dOKJcRjSZSC1HKQA1h0EVBoj5xLnWpu
Lh2bupup8gh+waYSpccl1DlWrBmT0iiPx/RvokChhof7TYBh8cA+6pme8RErOTqT
Hb4a84e3QEuxn6vb8xaxy/pQgVXkEAjq2+K3zdMRfwfDkitOes3GdlDxxfXWzsUi
UevucDWdknRaMyOW/qcSNbut3ja1eIe1Gj3O54TsxG4EJekxysqEkG1AjlquRqTz
6qDAb7ZMhrg2KemvknB4jYXwY2F/+vuelSzfyB5Dbnqpp5D4rwDEwM4OUB66l9Y6
9fFQmNxI2tKTp+b14XeFWHA0m87PAx+PBFNzjfGA2NrH21lSdKGLuevQaCrQ7JG6
h+2vP9hxF/VY6+eS0v8DQOD36kI7oLH57MRCXpYstlkyxs5lHrqi8agpHEY+exFN
Ev45NTxZA34MuNNK7RoQeXD5csug7IYd4fmnbnjOK4FNLtBzgo7eRWgDdgGSZ5ob
YB9UE9YGL+kupnV6TosyRUIPlbDnWE+JTXrJr9q+0ozfgrQp2lC0Brxd0PEEOlUN
wNyL5WVZ/JG0pCQfNYyDqpSHA1EomaYhxVZjiAypb4bWOL+Bdk97d8Q/gGmw6zGS
86mGfKi3K2qOU6ILuB2H9l6si1NTup6FKqxja710M02rp4ETVL4=
=jHJf
—–END PGP SIGNATURE—–


