Cisco Unified CM Flaw Grants Root
Cisco released fixes for a critical flaw in Unified Communications Manager that hands attackers root access on the appliance.
The bug is an SSRF flaw in the WebDialer service that lets unauthenticated attackers write arbitrary files to the OS, which can then be leveraged to escalate privileges to root. WebDialer is off by default but commonly enabled in enterprise deployments.
CVE-2026-20230 carries a CVSS base score of 8.6, though Cisco rates it Critical due to root escalation potential. Public PoC code appeared alongside the advisory.
Affects Unified CM versions 14 and 15 on on-prem appliances and certain hosted deployments. No other Cisco products are impacted.
Public PoC code is available. Cisco has not confirmed active exploitation as of the advisory.
