Cisco warns of critical Unified CM flaw with PoC exploit code
Cisco has issued a critical security update addressing a vulnerability (CVE-2026-20230) in its Unified Communications Manager (Unified CM) software. This flaw allows attackers to gain root privileges through SSRF attacks, potentially leading to system compromise. While currently unconfirmed, Cisco’s assessment deems the risk critical due to the potential for privilege escalation.
The vulnerability stems from a server-side request forgery (SSRF) attack that can be exploited remotely. An attacker could craft a malicious HTTP request to an affected Unified CM system, enabling them to write files to the underlying operating system and subsequently elevate their privileges to root access. Cisco’s Product Security Incident Response Team (PSIRT) is aware of publicly available proof-of-concept exploit code, but hasn't yet observed active exploitation. The vulnerability specifically impacts systems where the WebDialer service is enabled, a feature that is disabled by default.