CVE-2026-20060: Cisco Unity Connection Open Redirect Vulnerability
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious web page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20060?
CVE-2026-20060 is categorized as a high severity vulnerability due to its potential impact on user redirection to malicious sites.
How do I fix CVE-2026-20060?
To fix CVE-2026-20060, ensure that you apply the latest patches provided by Cisco for the Unity Connection software.
Who is affected by CVE-2026-20060?
Organizations using the affected versions of Cisco Unity Connection are at risk of CVE-2026-20060.
What are the risks associated with CVE-2026-20060?
The risks associated with CVE-2026-20060 include potential phishing attacks and redirection to malicious websites.
Can CVE-2026-20060 be exploited remotely?
Yes, CVE-2026-20060 can be exploited by unauthenticated, remote attackers.