CVE-2026-20230 is a critical SSRF vulnerability in Cisco Unified CM and SME that allows remote attackers to escalate to root privileges. Patches available.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| unified_communications_manager | 14.0 | 14su6 | vulnerable |
| unified_communications_manager | 14.0 | 14su6 | vulnerable |
| unified_communications_manager | 15.0 | 15su4a | vulnerable |
| unified_communications_manager | 15.0 | 15su4a | vulnerable |
Cisco has released software updates to address this SSRF vulnerability. Administrators should consult the Cisco Security Advisory (cisco-sa-cucm-ssrf-cXPnHcW) to identify and apply the appropriate fixed release for their specific deployment.
Upgrade Cisco Unified CM and SME instances to version 14su6 or later. For version 15.0 deployments, ensure you migrate to a release beyond 15su4a or apply the specific hotfixes recommended by Cisco to close the vulnerability.
If immediate patching is not possible, disable the WebDialer service, which is a prerequisite for exploitation. Additionally, implement network access control lists (ACLs) to restrict access to the Unified CM management interface to trusted, authorized internal networks only.
Audit system logs for unusual HTTP requests targeting the WebDialer service, specifically those containing suspicious URLs or file paths. Monitor the underlying operating system for unauthorized file creation or unexpected attempts to gain root-level access.
Detection should focus on monitoring HTTP traffic to the WebDialer service for malformed requests or SSRF patterns. Security teams should use EDR tools to monitor for unexpected processes running with root privileges and audit system integrity for unauthorized file writes. Network-level signatures should flag outbound requests originating from the Unified CM that target internal infrastructure or sensitive metadata services, which may indicate an active SSRF exploit attempt.
Experience superior visibility and a simpler approach to cyber risk management