File Download Vulnerability in Cisco Unity Connection
CVE-2026-20078
6.5MEDIUM
What is CVE-2026-20078?
Multiple vulnerabilities in Cisco Unity Connection permit an authenticated remote attacker to download arbitrary files from affected systems. These vulnerabilities arise from improper sanitization of user input within the web-based management interface. An attacker with valid administrative credentials may exploit this vulnerability by sending a specially crafted HTTPS request, potentially exposing sensitive files and data.
Affected Version(s)
Cisco Unity Connection 12.5(1)
Cisco Unity Connection 12.5(1)SU1
Cisco Unity Connection 12.5(1)SU2