CVE-2026-20078
Cisco Unity Connection Arbitrary File Download Vulnerability
Description
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials. These vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from an affected system.
Weakness: CWE-23
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Unity Connection | Other Products | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco Unity Connection
Vendor advisory
cisco-sa-unity-file-download-RmKEVWPx
Cisco Unity Connection Arbitrary File Download Vulnerabilities
Cisco’s rating: Medium (advisory CVSS 6.5) · Published Apr 15, 2026
Bug IDs: CSCwq36816 , CSCwr87730
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from