CVE-2026-20060 is an open redirect vulnerability affecting Cisco Unity Connection's web-based management interface. The flaw stems from improper input validation of HTTP request parameters, allowing an unauthenticated remote attacker to redirect users to malicious websites through crafted links. This vulnerability requires user interaction, as victims must click a malicious link to be redirected. The vulnerability carries a CVSS 3.1 score of 4.7 (medium severity) with a network-based attack vector and low complexity. No authentication is required for exploitation, though successful attacks depend on user interaction. The impact is limited to integrity compromise, with no confidentiality or availability impact expected. There is currently no evidence of active exploitation. The vulnerability does not appear on CISA's Known Exploited Vulnerabilities list and has not generated significant community attention. With an EPSS score of 0.00022, the probability of exploitation in the wild remains very low at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 12.5CPE matchmatch criteria | cpe:2.3:a:cisco:unity_connection:*:*:*:*:*:*:*:* | ||
14.0CPE matchmatch criteria | cpe:2.3:a:cisco:unity_connection:14.0:*:*:*:*:*:*:* | ||
14su1CPE matchmatch criteria | cpe:2.3:a:cisco:unity_connection:14su1:*:*:*:*:*:*:* | ||
14su2CPE matchmatch criteria | cpe:2.3:a:cisco:unity_connection:14su2:*:*:*:*:*:*:* | ||
14su3CPE matchmatch criteria | cpe:2.3:a:cisco:unity_connection:14su3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.