Executive brief
Cisco Unified Communications Manager, a system used for enterprise IP telephony and video calls, contains a security flaw that allows an unauthorized person to send malicious requests to the server. By exploiting this flaw, an attacker could remotely place files on the system's internal storage, which can then be used to gain full administrative control (root access) over the device. This could lead to a complete compromise of the communication system, allowing attackers to intercept calls or disrupt services.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Cisco Unified Communications Manager (Unified CM) and Session Management Edition (Unified CM SME) due to improper input validation of specific HTTP requests. An unauthenticated, remote attacker can exploit this by sending crafted HTTP requests to an affected device where the WebDialer service is enabled. Successful exploitation allows the attacker to perform arbitrary file writes to the underlying operating system. These files can subsequently be leveraged to achieve privilege escalation to root. While the CVSS score is 8.6, Cisco has classified this as Critical due to the potential for full system compromise. Note that the WebDialer service is disabled by default.
Affected products
- Cisco Unified Communications Manager (Unified CM)
- Cisco Unified Communications Manager Session Management Edition (Unified CM SME)
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory
- 2026-06-25: other: NVD record updated