SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-20314

MEDIUM · CVSS 5 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A vulnerability in Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise allows authenticated remote attackers to perform server-side request forgery (SSRF) attacks by exploiting improper input validation in specific HTTP requests. Successful exploitation could enable attackers to send arbitrary network requests from the affected device, potentially compromising internal systems. Organizations using these Cisco products should prioritize addressing this vulnerability to mitigate risks associated with unauthorized network access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-20314
Severity
MEDIUM
CVSS
5
EPSS
0.28%
Cisco

Original NVD Description

A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.