CVE-2026-20153 Details
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20153 are related to improper input validation that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.
A vulnerability has been identified in Cisco RoomOS releases 11 and earlier, as well as release 26, related to improper input validation. This vulnerability, part of a broader software hardening release, was discovered during internal security testing and is grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20. The issue affects Cisco RoomOS, regardless of device configuration.
Users are advised to upgrade to Cisco RoomOS version 11.32.6.0 or 26.5.2.2, depending on their current release. For RoomOS in cloud-aware operation, the first fixed release is RoomOS June 2026 (26.7.1.7).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco roomos | < 11.32.6.0 >= 26.0.1.2, < 26.5.2.2 |
CPE
Remediation
| |
| cisco roomos cloud | < 11.39.1.1 >= 26.0.1.2, < 26.7.1.7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 14, 2026 | CVE Modified | CVE |
| Aug 11, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | [email protected] |