Skip to content
CiscoCVE-2026-20314

Cisco Packaged Contact Center Enterprise: server-side request forgery

Medium5.0CVE-2026-20314 · Published Aug 19, 2026 · updated Aug 20, 2026

A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. 

Cisco advisory

Affected versions

PackageAffectedFixed in
Cisco Packaged Contact Center Enterprise
Product
<= 12.5(1)No fix yet
<= 11.0(1)No fix yet
<= 12.0(1)No fix yet
<= 11.0(2)No fix yet
Cisco Unified Contact Center Enterprise
Product
<= 12.6(1)ES3No fix yet
<= 12.6(1)ES1No fix yet
<= 12.6(1)No fix yet
<= 12.6(1)ES2No fix yet
Details and references

More Cisco advisories

All Cisco
Advisory
Cisco Secure Workload: improper input validation
Critical9.6Aug 19
Cisco Secure Workload: memory corruption
High7.5Aug 19
Cisco BroadWorks: XML external entity
High7.5Aug 19
Cisco Unified Intelligence Center: SQL injection
Medium6.5Aug 19
Cisco Crosswork Planning: missing authentication
Critical10.0Aug 19
As part of Cisco's ongoing commitment to proactive security and product quality
Critical10.0Aug 19

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.