CVE-2026-20061 | Cisco Unity Connection up to 15SU3 Web-based Management Interface sql injection (cisco-sa-unity-vulns-n2EJSbbw / EUVD-2026-22955)
A vulnerability was found in Cisco Unity Connection up to 15SU3. It has been classified as critical. Impacted is an unknown function of the component Web-based Management Interface. Performing a manipulation results in sql injection.
This vulnerability is reported as CVE-2026-20061. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.