VULNERABILITY OVERVIEW
An unauthenticated server-side request forgery (SSRF) flaw (CWE-918) in Cisco Unified CM's WebDialer component allows a remote attacker to send crafted HTTP requests that write arbitrary files to the underlying OS, which can then be leveraged to escalate privileges to root. SSD Secure Disclosure published a full PoC on June 23, 2026; within hours Defused Threat Intelligence confirmed active exploitation via honeypot telemetry observing file-write payloads. Cisco PSIRT confirmed active exploitation in June 2026 and updated the advisory; CISA added to KEV on June 25 (federal deadline June 28). WebDialer is disabled by default — only deployments with it enabled are exposed.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
CHANGED
C:N · I:H · A:N
AFFECTED VERSIONS
Cisco Unified CM and Unified CM SME versions prior to 14SU6 and 15SU5 with WebDialer service enabledCITATIONS
- → https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-cucm-ssrf-cXPnHcW.html
- → https://thehackernews.com/2026/06/cisco-unified-cm-flaw-exploited-after.html
- → https://horizon3.ai/attack-research/vulnerabilities/cve-2026-20230/
- → https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/