Get real-time updates on Telegram
CVE-2026-20230: unified communications manager from 14.0 (inclusive), before 14su6 (exclusive), from 15.0 (inclusive), through 15su4a…
CVE-2026-20230. CVSS 3.1 base score 8.6 (HIGH, Vendor/CNA). EPSS 0.882 (percentile 0.99766), scored 2026-10-06.
Affected technology
unified communications manager · from 14.0 (inclusive), before 14su6 (exclusive)
cisco
unified communications manager · from 15.0 (inclusive), through 15su4a (inclusive)
cisco
Cisco Unified Communications Manager · 14, 14SU1, 14SU2, 14SU3, 15, 15SU1, 14SU4, 14SU4a, 15SU1a, 15SU2, 15.0.1.13010-1, 15.0.1.13011-1, 15.0.1.13012-1, 15.0.1.13013-1, 15.0.1.13014-1, 15.0.1.13015-1, 15.0.1.13016-1, 15.0.1.13017-1, 15SU3a, 14SU5, 15SU4, 15SU4a
Cisco
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
An unauthenticated, remote attacker could conduct server-side request forgery (SSRF) attacks through an affected device. Vendor/CNA’s CVSS 3.1 assessment (base score 8.6/10) rates confidentiality and availability impact as none; integrity impact as high.
- CWE
- CWE-918
- CCR priority
- 56.5 /100 (P3)
- CVSS 3.1
- 8.6 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N · Vendor/CNA
- EPSS
- 0.882 · percentile 0.99766 · 2026-10-06
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 23:02:50.240617+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-20230.html