CVE Research
sekurity-team
InSEKurity of the Week (CW23/2026): Cisco Unified CM WebDialer Unauthenticated SSRF-to-Root (CVE-2026-20230)
Unauthenticated SSRF in the Cisco Unified Communications Manager WebDialer service lets remote attackers write files to the underlying OS and escalate to root -- public exploit code is already available
Exploit
01