CVE-2026-20059: Cisco Unity Connection Reflected Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20059?
CVE-2026-20059 is rated as a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2026-20059?
To mitigate CVE-2026-20059, apply the latest security patches provided by Cisco for Unity Connection.
Who is affected by CVE-2026-20059?
CVE-2026-20059 affects users of the web-based management interface of Cisco Unity Connection.
What type of attack is CVE-2026-20059 associated with?
CVE-2026-20059 is associated with reflected cross-site scripting (XSS) attacks.
Can CVE-2026-20059 be exploited remotely?
Yes, CVE-2026-20059 can be exploited by an unauthenticated, remote attacker.