Executive brief
Cisco Unity Connection, a unified messaging and voicemail platform, contains a vulnerability in its web management interface. An attacker with valid user credentials can exploit this flaw to take full control of the system. This could lead to the theft of sensitive communications, service disruption, or a complete compromise of the device.
Technical details
A vulnerability in the web-based management interface of Cisco Unity Connection (CWE-35: Path Traversal) allows an authenticated, remote attacker to execute arbitrary code as root. The issue stems from insufficient validation of user-supplied input within API requests. By submitting a specially crafted API request, an attacker with valid user credentials can bypass security controls to execute commands on the underlying operating system. Cisco has released software updates (14SU5 and 15SU4) to address this vulnerability; no workarounds are available.
Affected products
- Cisco Unity Connection 12.5 and earlier, 14.0 before 14SU5, 15.0 before 15SU4
Timeline
- 2026-05-06: advisory: Initial public release by Cisco
- 2026-05-06: disclosed