CVE-2026-20289 Details
Description
A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials.
A vulnerability exists in the logging subsystem of Cisco RoomOS, allowing an authenticated, local attacker with low privileges to access sensitive information. This issue arises from the logging of confidential data, such as user login credentials. Exploitation involves enabling a specific logging level and collecting the system logs, which could then reveal this sensitive information.
Cisco has released software updates to address this vulnerability. For RoomOS versions 11 and earlier, the first fixed release for on-premises operation will be in a future release, while version 11.39.1.3 is available for cloud-aware operation. For RoomOS version 26, the first fixed release for on-premises operation is 26.7.2.2, and RoomOS June 2026 (26.7.1.12) is available for cloud-aware operation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-infodisc-qBXjfmWm | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco roomos | >= 26.0.1.2, < 26.7.2.2 |
CPE
Remediation
| |
| cisco roomos cloud | < 11.39.1.3 >= 26.0.1.2, < 26.7.1.12 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 17, 2026 | Initial Analysis | [email protected] |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |