CVE-2026-20230

CVSS 8.6 · HIGH
EPSS p97
Higher than 97% of all CVEs — imminent exploitation likely.
No patch reference
No patch/mitigation in references

Published 6/3/2026 · updated 6/17/2026 · CWE-918

Share
Get asset-aware triage

Summary

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.

CVSS 8.6HIGH

8.6 / 10
  • AV: Network
  • AC: Low complexity
  • PR: No privileges
  • UI: No user interaction
  • S: Scope changed
  • C: Confidentiality: None
  • I: Integrity: High
  • A: Availability: None

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

EPSS exploitation probability

20.4%

Percentile p97 Higher than 97% of all CVEs — imminent exploitation likely.

Timeline

  1. Jun 3, 2026 · Disclosed / published in NVD
  2. Jun 17, 2026 · Intel last updated

Intel sources

Which upstream feeds returned data for this CVE, and when they were last fetched.

  • NVD· 40 days ago
  • CVE.org· no data
  • FIRST EPSS· 40 days ago
  • CISA KEV· no data
  • OSV· 40 days ago

References

Unlock the full report

See how CVE-2026-20230 hits your stack.

Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.

  • · Asset-aware CVSS & priority
  • · Grounded AI analysis (A–D graded)
  • · Auto-generated WAF / IPS rules
  • · Jira, SIEM, Slack, Teams delivery

No credit card · 100 free enrichments · analyst-grade citations.