Description
A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.

This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. 
Published: 2026-08-19
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper input validation for certain HTTP requests in Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise. An authenticated attacker can craft a malicious HTTP request to the device, tricking it into performing arbitrary network calls on the attacker’s behalf. This introduces a server‑side request forgery weakness (CWE‑918). The compromise could allow the attacker to reach internal or external resources, potentially exposing sensitive data, executing network‑level reconnaissance, or extending lateral movement. The impact is limited to the device from which the request originates and requires valid user credentials.

Affected Systems

Both Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise are affected. The advisory does not specify individual software versions; thus any installation of these products remains vulnerable until patched.

Risk and Exploitability

With a CVSS score of 5.0, the vulnerability is classified as moderate. Because the exploit requires authentication, the risk is constrained to accounts with administrative or privileged access to the affected device. EPSS data is not available, and the vulnerability is not listed in CISA KEV, indicating no known large‑scale exploitation yet. Nonetheless, a successful SSRF can be leveraged to breach internal networks or gather reconnaissance information, so caution is warranted.

Generated by OpenCVE AI on August 20, 2026 at 14:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied software update that resolves the SSRF flaw in Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise.
  • Restrict outbound traffic from the device by configuring firewall rules to allow only trusted destinations and block untrusted host addresses.
  • Review and minimize user permissions, ensuring that only essential accounts have remote access to the device; disable or revoke unused accounts.
  • Configure logging or monitoring to detect anomalous outbound connections initiated by the device.

Generated by OpenCVE AI on August 20, 2026 at 14:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco packaged Contact Center Enterprise
Cisco unified Contact Center Enterprise
Vendors & Products Cisco
Cisco packaged Contact Center Enterprise
Cisco unified Contact Center Enterprise

Wed, 19 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.&nbsp;
Title Cisco Packaged Contact Center Enterprise & Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

Cisco Packaged Contact Center Enterprise Unified Contact Center Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-19T19:33:48.763Z

Reserved: 2025-10-08T11:59:15.410Z

Link: CVE-2026-20314

cve-icon Vulnrichment

Updated: 2026-08-19T19:33:39.167Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T17:18:39.677

Modified: 2026-08-20T13:01:19.947

Link: CVE-2026-20314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T14:15:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)