Description
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP(S) request to the web-based management interface of an affected device. A successful exploit could allow the attacker to view data on the affected device.
Published: 2026-04-15
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidential Data Disclosure
Action: Apply Patch
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:cisco:unity_connection:12.5:*:*:*:*:*:*:* cpe:2.3:a:cisco:unity_connection:*:*:*:*:*:*:*:*

Tue, 28 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:cisco:unity_connection:12.5:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unity_connection:14.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unity_connection:14su1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unity_connection:14su2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unity_connection:14su3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unity_connection:14su3a:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unity_connection:14su4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unity_connection:14su5:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unity_connection:15.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unity_connection:15su1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unity_connection:15su2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unity_connection:15su3:*:*:*:*:*:*:*

Wed, 15 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco unity Connection
Vendors & Products Cisco
Cisco unity Connection

Wed, 15 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP(S) request to the web-based management interface of an affected device. A successful exploit could allow the attacker to view data on the affected device.
Title Cisco Unity Connection SQL Injection Vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Cisco Unity Connection
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-04-15T16:56:34.089Z

Reserved: 2025-10-08T11:59:15.356Z

Link: CVE-2026-20061

cve-icon Vulnrichment

Updated: 2026-04-15T16:56:14.498Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-15T17:17:01.433

Modified: 2026-04-28T16:30:48.730

Link: CVE-2026-20061

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T22:30:16Z

Weaknesses