CVE-2026-20045: Cisco Unified Communications Products Code Injection Vulnerability
Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified…
Cisco Unified Communications Manager and related products contain a code injection vulnerability tracked as CVE-2026-20045. The flaw affects Cisco Unified Communications Manager, Unified CM Session Management Edition, Unified CM IM & Presence Service, Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance. Successful exploitation can let an attacker obtain user-level access to the underlying operating system and then raise privileges to root.
The issue matters for organizations that rely on these products for voice, video, and messaging services because root access on the host can expose call detail records, configuration data, and connected infrastructure.
How it works
The weakness is classified as CWE-94, improper control of code generation. An attacker supplies input that the application treats as executable code rather than data. This allows the attacker to run commands that establish an initial user-level foothold on the operating system. From that position the attacker can attempt further actions to reach root privileges. Specific injection vectors and required preconditions are not detailed in the summary and must be confirmed against the vendor advisory.
Am I affected? How to find it in your systems
- Inventory all deployments of Cisco Unified Communications Manager, Unified CM SME, Unified CM IM&P, Cisco Unity Connection, and Webex Calling Dedicated Instance.
- Use Cisco-provided management consoles, license reports, and network discovery tools to locate instances that may run the affected software.
- Compare installed versions and configurations against the vendor advisory, because not every release or deployment option is necessarily vulnerable.
- Review authentication logs, process execution records, and administrative access attempts for anomalies that could indicate attempts to reach the operating system shell.
How to remediate
Apply the vendor-supplied update referenced in the official advisory as the primary remediation. After patching, review and restrict any administrative interfaces or scripting features that accept untrusted input. Follow the principle of least privilege for accounts that manage these systems and disable unnecessary services that could expand the attack surface.
If you can't patch immediately
- Apply mitigations exactly as described in the vendor instructions.
- For any cloud-hosted instances, follow applicable CISA BOD 22-01 guidance.
- If mitigations cannot be implemented, discontinue use of the affected product until a fix is available.
- Segment the Unified Communications infrastructure from general-purpose networks and monitor for unexpected outbound connections or privilege-escalation events.
If your data may have been exposed
Code injection flaws that reach the operating system have led to data exposure in other incidents. Organizations can run a free exposure scan of their email addresses against known breach data to check for signs of prior compromise.
AICompiled with AI assistance from public sources and published under our editorial standards.