CVE-2026-20045
Cisco Unified Communications Products Remote Code Execution Vulnerability
Cisco Unified Communications Products Code Injection Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA notes
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b ; https://nvd.nist.gov/vuln/detail/CVE-2026-20045
Description
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:NAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| Cisco | Cisco Unified Communications Manager | 12.5(1)SU2 12.5(1)SU1 12.5(1) 12.5(1)SU3 12.5(1)SU4 14 12.5(1)SU5 14SU1 12.5(1)SU6 14SU2 12.5(1)SU7 12.5(1)SU7a 14SU3 12.5(1)SU8 12.5(1)SU8a 15 15SU1 14SU4 14SU4a 15SU1a 12.5(1)SU9 15SU2 15.0.1.13010-1 15.0.1.13011-1 15.0.1.13012-1 15.0.1.13013-1 15.0.1.13014-1 15.0.1.13015-1 15.0.1.13016-1 15.0.1.13017-1 15SU3a |
| Cisco | Cisco Unified Communications Manager IM and Presence Service | 12.5(1) 12.5(1)SU1 12.5(1)SU2 12.5(1)SU3 12.5(1)SU4 14 12.5(1)SU5 14SU1 12.5(1)SU6 14SU2 14SU2a 12.5(1)SU7 14SU3 12.5(1)SU8 15 15SU1 14SU4 12.5(1)SU9 15SU2 15SU3 |
| Cisco | Cisco Unity Connection | 12.5(1) 12.5(1)SU1 12.5(1)SU2 12.5(1)SU3 12.5(1)SU4 14 12.5(1)SU5 14SU1 12.5(1)SU6 14SU2 12.5(1)SU7 14SU3 12.5(1)SU8 14SU3a 12.5(1)SU8a 15 15SU1 14SU4 12.5(1)SU9 15SU2 15SU3 |
References
1 LinksRecord Details
More from Cisco
Cisco HyperFlex HX Command Injection Vulnerabilities
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
Cisco HyperFlex HX Command Injection Vulnerabilities
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.