---
schema: 1
kind: vulnerability
title: "CVE-2026-20230 — Cisco Unified CM: WebDialer SSRF to arbitrary file write to root, reconnaissance-stage exploitation observed"
headline: "CVE-2026-20230 — Cisco Unified CM: WebDialer SSRF to arbitrary file write to root, reconnaissance-stage exploitation observed"
summary: "Cisco Unified CM CVE-2026-20230 (WebDialer SSRF → arbitrary file write → root, CVSS 8.6) is now seeing reconnaissance-stage exploitation in the wild and a public PoC — patch 14SU6 / the 15-train COP, or disable WebDialer. (BleepingComputer, 2026-06-23)."
discovered_at: "2026-06-24T05:11:49Z"
event_date: 2026-06-23
run_id: 2026-06-24-de656486
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - pre-auth
  - poc-public
  - patch-available
  - rce
regions:
  - global
sectors:
  - technology
entities: []
cves:
  - id: CVE-2026-20230
    cvss: "8.6"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - poc-public
      - patch-available
sources:
  - url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW"
    publisher: Cisco PSIRT advisory cisco-sa-cucm-ssrf-cXPnHcW
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/"
    publisher: BleepingComputer
    role: corroborating
closed_sources: []
evidence:
  - quote: A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.
    publisher: Cisco PSIRT
  - quote: the PoC observed by Defused appears designed to identify vulnerable devices
    publisher: BleepingComputer
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Remediate Cisco Unified CM CVE-2026-20230** if WebDialer is enabled on an internet-facing instance: apply 14SU6 (Release 14) or the Release-15 COP fix, or disable the Cisco WebDialer Web Service if unused; hunt WebDialer logs for `file://` URIs and stray file-creation events (§ 2)."
migrated_from: briefs/2026-06-24.md
---

Cisco PSIRT's advisory (2026-06-03) for **CVE-2026-20230** (CVSS 8.6, CWE-918 SSRF) describes a flaw in the WebDialer service of Cisco Unified Communications Manager (Unified CM) releases 14 and 15: the service fails to validate HTTP requests, so an unauthenticated remote attacker can send a crafted request with a `file://` payload to write arbitrary files to the underlying OS, which Cisco states can subsequently be used to escalate to root ([Cisco PSIRT, 2026-06-03](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW); [BleepingComputer, 2026-06-23](https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/)). WebDialer is disabled by default, so exposure requires it to have been enabled. Threat-intelligence firm Defused observed exploitation over the weekend of ~2026-06-21/22 from a single source IP, writing a marker file (`/tmp/cve-2026-20230-test.txt`) — a vulnerability-fingerprinting pattern that historically precedes a targeted exploitation wave. A public PoC (SSD Secure Disclosure) exists. Not KEV-listed as of this run. Patched in 14SU6 for Release 14, with a COP interim fix for Release 15 (full 15SU5 is not due until September 2026). Maps to `T1190` (Exploit Public-Facing Application) and `T1068` (privilege escalation via the written file). Defenders with internet-facing Unified CM should disable WebDialer if unused (Service Parameters → Cisco WebDialer Web Service), and hunt WebDialer access logs for `file://` URIs and unexpected file-creation events (Sysmon EID 11 / `auditd`) outside normal WebDialer paths — without treating absence of the marker file as proof of safety, since it is trivially cleaned up.
