Junglewise Threat Intelligence

CVE-2026-20035: Cisco Unity Connection SSRF in Web Inbox

CVE-2026-20035 · Severity: high · CVSS 7.2 · Published 2026-05-06

Technologies: Cisco Unity Connection. Vendors: Cisco.

Executive brief

A vulnerability in the Cisco Unity Connection Web Inbox could allow an unauthorized person to use the system as a proxy to send network requests. This feature, which allows users to manage voicemails via a web browser, is enabled by default. An attacker could exploit this to probe internal network resources that are otherwise protected or to mask the origin of malicious traffic, potentially leading to unauthorized data access or further internal attacks.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the web UI of Cisco Unity Connection Web Inbox due to improper input validation of specific HTTP requests. An unauthenticated, remote attacker can exploit this by sending a crafted HTTP request to the affected device. A successful exploit allows the attacker to source arbitrary network requests from the device, potentially reaching internal systems or services that are not directly accessible from the external network. The vulnerability is present if the 'Allow Users to Use the Web Inbox and RSS Feeds' feature is enabled (default setting). Cisco has released software updates to address this issue; no workarounds are available.

Affected products

  • Cisco Unity Connection 12.5 and earlier, 14.0 before 14SU5, 15.0 before 15SU4

Timeline

  • 2026-05-06: advisory: Initial public release by Cisco
  • 2026-05-06: patched: Fixed in 14SU5 and 15SU4

References

Related threats