CVE-2026-20230

unified_communications_manager: Server-Side Request Forgery (SSRF) (CVE-2026-20230)

Situation assessment

An unauthenticated, remote attacker can exploit a server-side request forgery (SSRF) vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) to write files to the underlying operating system, potentially leading to root privilege escalation. The vulnerability, due to improper input validation for specific HTTP requests, is actively exploited in the wild and requires the WebDialer service to be enabled. Affected versions include 14.0 to 14su6 and 15.0 to 15su4a. Immediate patching to the latest available version is critical.

Affected

  • cisco/unified_communications_manager between 14.0..14su6
  • cisco/unified_communications_manager between 14.0..14su6
  • cisco/unified_communications_manager between 15.0..15su4a
  • cisco/unified_communications_manager between 15.0..15su4a

Response & Mitigation

Why act now?

Prioritisation rationale

With an EPSS score of 88.2 % (99.8th percentile) and a CVSS v3 score of 8.6 (Scope: Changed, Integrity: High, no authentication required), this vulnerability carries an outsized real-world risk that Cisco itself has escalated to a Critical SIR rating, because successful exploitation leads to root-level privilege escalation — not merely SSRF data leakage. The sole prerequisite is an enabled WebDialer service, which is common in organisations using click-to-dial functionality, making the effective attack surface broader than a default-off feature might suggest. For NIS2-scoped organisations in telecommunications, healthcare, or public administration running Unified CM, a compromised UC server represents a high-value pivot point into internal network segments and telephony infrastructure. Disabling WebDialer is the single highest-impact, patch-independent control and must be validated before any other remediation step is taken.

Runbook · Step 1

Immediate response (0-24 h)

  • Disable the WebDialer service immediately: Cisco Unified CM → Cisco Unified Serviceability → Tools → Service Activation → deactivate „Cisco WebDialer Web Service". WebDialer is disabled by default but must be confirmed off — without it, no attack path exists.
  • Apply vendor patch: Cisco has released fixes for affected release trains. For Unified CM 14.x: upgrade to 14SU7 or later; for 15.x: upgrade to 15SU5 or later — verify exact build numbers in Cisco Security Advisory CSCwm64819 on cisco.com/security, as patch identifiers may be updated after this playbook's publication.
  • Block external access to WebDialer ports: Immediately enforce firewall rules denying TCP 8080 and 8443 from the internet and any untrusted network segment to all Unified CM nodes. These ports should only be reachable from authorised internal endpoints.
  • Scan for suspicious file writes: Perform a filesystem review of /usr/local/cm/, /common/download/, and OS temp directories for files created or modified in the last 72 hours that fall outside expected patch activity.
  • Preserve audit logs: Export and immutably archive current syslog and audit logs from the Unified CM cluster before any patch-related reboot triggers log rotation.

Runbook · Step 2

Mitigation layers

  • Network segmentation: Place all Unified CM nodes in a dedicated UC VLAN; restrict inbound HTTP/HTTPS (TCP 8080/8443) to an explicit allowlist of internal UC clients and gateways — no direct access from DMZ or internet.
  • WAF / reverse-proxy rule: If a reverse proxy fronts Unified CM, block requests containing internal RFC-1918 addresses, localhost, or SSRF-indicative URL schemes (file://, gopher://, dict://) in Host headers or request bodies. Suricata/Snort: alert on http.uri matching file://, gopher://, or http://169.254. targeting port 8080/8443.
  • Least-privilege OS hardening: Confirm Unified CM Tomcat processes do not run as root; audit filesystem ACLs on directories writable by the WebDialer process and restrict them to the minimum required.
  • File-integrity monitoring (FIM): Deploy host-based FIM on critical Unified CM OS directories; alert on any unexpected write outside a defined maintenance window: auditctl -w /usr/local/cm/ -p wa -k ucm_ssrf_write
  • Restrict admin-plane access: Expose the Unified CM Administration GUI (TCP 443/8443) only via a dedicated management VLAN with MFA-enforced jump-host access; block direct admin access from production VLANs.

Runbook · Step 3

Detection rules

  • Web-server access logs (Unified CM / Apache Tomcat): Alert on HTTP requests to /webdialer/ or /ccmwebapi/ containing internal IPs, localhost, 127.0.0.1, 169.254.169.254, or non-HTTP URL schemes in parameters or Host headers. SPL: index=ucm sourcetype=access_combined uri_path="/webdialer/*" (url="*file://*" OR url="*127.0.0.1*" OR url="*169.254.*")
  • auditd filesystem telemetry: Monitor for openat/write syscalls by the Tomcat process (comm="java") to paths outside expected application directories: auditctl -w /usr/local/cm/ -p wa -k ucm_ssrf_write; correlate with preceding anomalous HTTP requests.
  • Network telemetry (Zeek / Suricata): Detect outbound connections originating from the Unified CM host to internal RFC-1918 ranges or cloud metadata endpoints (169.254.169.254) — a strong indicator of SSRF pivoting. Zeek conn.log: filter id.orig_h == <UCM-IP> with id.resp_h in internal ranges that are not legitimate UC destinations.
  • Sigma rule shape: title: Cisco UCM WebDialer SSRF File Write — trigger: process java (Tomcat) creates files in /tmp/ or /common/download/ with unexpected extensions outside maintenance windows; data source: auditd or EDR file-creation telemetry.
  • Post-exploitation privilege escalation: Correlate unexpected root logins or sudo escalations on Unified CM nodes with timestamps of anomalous WebDialer HTTP requests. auditd: type=USER_AUTH uid=0 from non-administrative processes; cross-reference with web-access log timestamps.

Description

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

ciscounified_communications_manager
14.0 – 14su615.0 – 15su4a

Metrics

8.6
Source: nvd-v3
99.8 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Actively exploited
Show all metrics
Severity
critical
actively exploited (KEV)
88.2 %
High — model estimates ≥ 50% chance of real-world exploitation within 30 days.
Published
2026-06-03 18:16 UTC
CWE-918

Weakness classes (CWE)

  • CWE-918Base

    Server-Side Request Forgery (SSRF)

    The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

    cwe.mitre.org →

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-07 19:17 UTC· psirt@cisco.com
    • Reference: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW
    • Reference: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW
    • Reference Type: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW Types: Vendor Advisory
  2. CVE Modified2026-10-07 19:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/
    • Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20230
    • Reference: https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/
    • Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20230
  3. CVE Translated2026-07-22 19:10 UTC· nvd@nist.gov
    • Translation: Title: Cisco Unified Communications Manager de Cisco, Description: Una vulnerabilidad en Cisco Unified Communications Manager (Unified CM) y Cisco Unified Communications Manager Session Management Edition (Unified CM SME) podría permitir a un atacante remoto no autenticado realizar ataques de falsificación de petición del lado del servidor (SSRF) a través de un dispositivo afectado. Esta vulnerabilidad se debe a una validación de entrada incorrecta para peticiones HTTP específicas. Un atacante podría explotar esta vulnerabilidad enviando una petición HTTP manipulada a un dispositivo afectado. Un exploit exitoso podría permitir al atacante escribir archivos en el sistema operativo subyacente que podrían usarse más tarde para elevar a root. Nota: Cisco ha asignado a este aviso de seguridad una Calificación de Impacto de Seguridad (SIR) de Crítica en lugar de Alta, como indica la puntuación. La razón es que la explotación de esta vulnerabilidad podría resultar en que un atacante eleve privilegios a root. Nota: Para explotar esta vulnerabilidad, el servicio WebDialer debe estar habilitado. WebDialer está deshabilitado por defecto.
  4. Modified Analysis2026-07-01 18:15 UTC· nvd@nist.gov
  5. CVE Modified2026-07-01 17:16 UTC· psirt@cisco.com
    • Affected: Cisco Unified Communications Manager → Cisco Unified Communications Manager
    • Description: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default. → A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.

Linked advisories