Home

Description

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

PUBLISHED Reserved 2025-10-08 | Published 2026-04-15 | Updated 2026-04-15 | Assigner cisco




MEDIUM: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Problem types

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
unknown

14
affected

14SU1
affected

14SU2
affected

14SU3
affected

14SU3a
affected

15
affected

15SU1
affected

14SU4
affected

15SU2
affected

15SU3
affected

14SU5
affected

15SU4
affected

References

sec.cloudapps.cisco.com/...ory/cisco-sa-unity-vulns-n2EJSbbw (cisco-sa-unity-vulns-n2EJSbbw)

cve.org (CVE-2026-20059)

nvd.nist.gov (CVE-2026-20059)

Download JSON