---
schema: 1
kind: vulnerability
title: "CVE-2026-20230 — Cisco Unified Communications Manager: unauthenticated SSRF to OS-root file write"
headline: "CVE-2026-20230 — Cisco Unified Communications Manager: unauthenticated SSRF to OS-root file write"
summary: "Two critical advisories hit public-sector infrastructure defenders run themselves: an unauthenticated SSRF-to-root in Cisco Unified CM (CVE-2026-20230) and an OTP-bypass in MISP (CVE-2026-10611) — the threat-intel platform deployed across EU/CH national CERTs."
discovered_at: "2026-06-04T05:00:07Z"
event_date: 2026-06-03
run_id: 2026-06-04-51b23ffa
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - pre-auth
  - priv-esc
  - poc-public
  - patch-available
regions:
  - global
  - europe
  - switzerland
sectors:
  - public-sector
  - healthcare
  - telco
entities: []
cves:
  - id: CVE-2026-20230
    cvss: "8.6"
    epss: null
    type: priv-esc
    vector: zero-click
    auth: pre-auth
    status:
      - poc-public
      - patch-available
sources:
  - url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW"
    publisher: Cisco PSIRT advisory cisco-sa-cucm-ssrf-cXPnHcW
    role: primary
closed_sources: []
evidence:
  - quote: A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root
    publisher: Cisco PSIRT
verification: single-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-04.md
---

Cisco PSIRT disclosed an SSRF in the Unified CM / Unified CM SME WebDialer service where improper HTTP input validation lets an unauthenticated remote attacker coerce the device into fetching an attacker URL and writing the response to arbitrary OS locations — a write primitive Cisco states "could be used later to elevate to root" via a drop into cron/service directories ([Cisco PSIRT, 2026-06-03](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW)). Cisco rates it Critical (SIR) despite CVSS 8.6 because of the root path. WebDialer is disabled by default; affected are Release 14 (pre-14SU6) and 15 (pre-15SU5). Cisco reports no confirmed in-the-wild exploitation at disclosure but states that proof-of-concept exploit code is publicly available — which compresses the window before opportunistic exploitation. Disable WebDialer if unused, patch to 14SU6 / apply the Release 15 COP, restrict admin-interface access to management networks, and hunt for unexpected outbound HTTP from Unified CM hosts.
