boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-20230HIGH
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  N  H  N    8.6   .8321   99.7   YES
AFFECTED
  Product                               Versions  Fixed
  Cisco Unified Communications Manager  14 –      —
TIMELINE
  Oct 8   Reserved by cisco
  Jun 25  Added to CISA KEV, remediation due 2026-06-28
  Jun 25  Published (CNA: cisco)
  Jun 29  DUE DATE PASSED — CVE-2026-20230 (Cisco Unified Communications Manager). CISA remediation deadline was June 28, 2026; still in catalog.
  Jul 22  ENRICHED — CVE-2026-20230 (Cisco Unified Communications Manager). Received CVSS 8.6 and CPE data from NVD.
  Jul 22  EXPLOIT PUBLISHED — CVE-2026-20230 (Cisco Unified Communications Manager). Public exploit reference added.
CWE-918 · CNA: cisco · CVSS v3.1 · 3 references · NVD status: Analyzed · KEV due June 28, 2026

Description

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.

Lifecycle

Complete event history — 6 events, chronological
DateEventDetail
October 8, 2025ReservedReserved by cisco
June 25, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-06-28
June 25, 2026PublishedPublished (CNA: cisco)
June 29, 2026DUE DATE PASSEDDUE DATE PASSED — CVE-2026-20230 (Cisco Unified Communications Manager). CISA remediation deadline was June 28, 2026; still in catalog.
July 22, 2026ENRICHEDENRICHED — CVE-2026-20230 (Cisco Unified Communications Manager). Received CVSS 8.6 and CPE data from NVD.
July 22, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-20230 (Cisco Unified Communications Manager). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
CiscoCisco Unified Communications Manager14

Weaknesses

CWE-918

References (3)

Related

Authoritative record: CVE-2026-20230 at cve.org

Vendors: cisco

Weaknesses: CWE-918

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-20230 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.