CVE-2026-20470: Medium severity Telephony vulnerability
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11086431; Issue ID: MSV-8189.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS11086431 - Compensating control
Apply the security patch corresponding to Issue ID MSV-8189 (ALPS11086431) to address the missing permission check that may allow local information disclosure without additional execution privileges.