CVE-2026-20230: SSRF Vulnerability in Cisco Unified CM SME, EITW

Last Updated: June 26, 2026 4:28 PM

What’s Happening

CVSSv3: 8.6

Initially published by Cisco on June 3rd, 2026 this vulnerability has been found EITW. A patch is available. It has no workarounds. This vulnerability requires WebDialer to be enabled (disabled by default). Cisco is treating it as a critical vulnerability because it allows for root privilege escalation. A POC was made publicly available on Github as of June 4th, 2026.

Cisco’s Advisory:

Actions

Update to the latest version of Cisco Unified CM SME. Disable WebDialer if it’s not needed.

Notes

https://www.cve.org/CVERecord?id=CVE-2026-20230

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34137

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20230

https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/