Vulnerabilità · 167 giorni fa

Cisco Unity Connection Bugs Expose Admin Web Sessions

Cisco Unity Connection’s web management interface can be abused to run script in an admin’s browser or send users to a malicious site. The standard response is to treat this as a low-grade web bug, but on a management plane that handles voice infrastructure, browser compromise can expose privileged sessions and internal admin workflows.

Cisco says CVE-2026-20059 is a reflected XSS flaw and CVE-2026-20060 is an open redirect flaw. Both affect Cisco Unity Connection and are fixed in vendor software updates; Cisco says there are no workarounds.

The immediate risk is not service outage. It is that an attacker can turn a trusted admin link into a session-theft or lure path against the people who manage the system.

CVE-2026-20059

NVD KEV

CVSS 6.1 MEDIUM: a vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated…

CVE-2026-20060

NVD KEV

CVSS 4.7 MEDIUM: a vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated…

Cronologia

Fonti

3 fonti che coprono questa storia

Entità

Riepilogo fornitore: Cisco

Part of the PlainSec briefing for 2026-04-16

Editions

Storie correlate