CVE-2026-20034 Details
Description
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of a targeted device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
A remote code execution vulnerability has been identified in the web-based management interface of Cisco Unity Connection. This vulnerability allows an authenticated, remote attacker to execute arbitrary code on the affected device. The issue arises from inadequate validation of user-supplied input, enabling attackers to exploit it by sending crafted API requests. Successful exploitation could allow the attacker to execute code with root privileges, potentially leading to a complete compromise of the device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
Cisco has released software updates to address this vulnerability. Users can upgrade to the fixed releases mentioned in the Cisco Security Advisory. For versions 15.0, a specific patch file is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-rce-ssrf-hENhuASy | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-35 | Path Traversal: '.../...//' | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco unity connection | < 14.0 14.0 14su1 14su2 14su3 14su4 15.0 15su1 15su2 15su3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | New CVE Received | [email protected] |