Junglewise Threat Intelligence

CVE-2026-20314: Cisco Packaged CCE and Unified CCE server-side request forgery

CVE-2026-20314 · Severity: medium · CVSS 5 · Published 2026-08-19

Vendors: Cisco.

Executive brief

Cisco's Packaged Contact Center Enterprise and Unified Contact Center Enterprise are telecommunications systems that manage customer interactions across multiple channels. A vulnerability allows authenticated users to send forged network requests from the affected system, potentially accessing internal systems or exfiltrating data that the contact center can reach. An attacker requires valid login credentials to exploit this flaw.

Technical details

This is a server-side request forgery (CWE-918) vulnerability caused by improper input validation of HTTP requests in Cisco Packaged CCE and Unified CCE. The vulnerability requires an authenticated remote attacker to send a crafted HTTP request to the affected device; once successful, arbitrary network requests can be forged with the device as the origin. This allows attackers to access internal systems, bypass network segmentation, or probe services that trust the contact center infrastructure. Cisco released fixed software versions, with Cisco Packaged CCE and Unified CCE 15.0(1)ES202607 and later addressing the issue.

Affected products

  • Cisco Packaged Contact Center Enterprise Earlier than 15.0(1)ES202607
  • Cisco Unified Contact Center Enterprise Earlier than 15.0(1)ES202607

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed releases available: Packaged CCE and Unified CCE 15.0(1)ES202607 and later

References