CVE-2026-20314

MEDIUMCVSS 5/10

Last modified

CVE-2026-20314 is a medium-severity vulnerability rated 5/10 on the CVSS scale. A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device.

Description

A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. 

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
CiscoCisco Packaged Contact Center Enterprise12.5(1); 11.0(1); 12.0(1); 11.0(2); 11.5(1); 10.5(1); 10.5(2); 11.6(2); 10.5(1)_ES7; 11.6(1); 10.5(2)_ES8; 12.5(2); 12.6(2); 15.0(1)
CiscoCisco Unified Contact Center Enterprise12.6(1)ES3; 12.6(1)ES1; 12.6(1); 12.6(1)ES2; 12.6(1)SecurityPatch; 12.5(1)ES1; 12.5(1); 12.6(1)ES4; 11.0(1); 10.5(1); 12.0(1); 10.5; 11.0; 11.5; 12.6(2); 12.6(2)ES1; 12.6(2)ES2; 15.0(1); 12.6(2)ES3; 15.0(1)ET01; 15.0(1)_SP1; 15.0(1)ES202508; 15.0(1)ES202511; 12.6(2)ES4; 15.0(1)SU1; 15.0(1)ES202603; 12.6(2)ES5

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-20314?
A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. 
How severe is CVE-2026-20314?
CVE-2026-20314 has a CVSS score of 5/10 (MEDIUM severity).
How do I fix CVE-2026-20314?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-20314?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST