Improper Input Validation in Cisco Unity Connection Management Interface
CVE-2026-20060

4.7MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
15 April 2026

Badges

👾 Exploit Exists

What is CVE-2026-20060?

A flaw in the web-based management interface of Cisco Unity Connection allows remote attackers to execute unauthorized actions. Due to inadequate validation of HTTP request parameters, malicious actors can potentially lure users into clicking crafted links. Successfully exploiting this weakness could redirect unsuspecting users to harmful web pages, posing significant security risks.

Affected Version(s)

Cisco Unity Connection 14

Cisco Unity Connection 14SU1

Cisco Unity Connection 14SU2

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.