CiscoCVE-2026-20289
Cisco RoomOS Software: information disclosure
Medium5.7CVE-2026-20289 · Published Aug 5, 2026 · updated Aug 17, 2026
A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cisco RoomOS Software Product | <= RoomOS 10.11.2.2 | No fix yet |
| <= RoomOS 10.15.2.2 | No fix yet | |
| <= RoomOS 11.5.4.6 | No fix yet | |
| <= RoomOS 11.5.2.4 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-532
More Cisco advisories
All Cisco| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 5 | Cisco Catalyst SD-WAN: cleartext secrets | High8.8 | No fix yet |
| Aug 5 | Cisco Catalyst SD-WAN: improper quantity validation | High7.7 | No fix yet |
| Aug 5 | Cisco IOS XE Software: denial of service | Medium4.3 | No fix yet |
| Aug 5 | Cisco Catalyst SD-WAN: link following | Critical9.1 | No fix yet |
| Aug 5 | Cisco IOS XE Software: denial of service | Medium6.3 | No fix yet |
| Aug 5 | Cisco IOS XE Software: denial of service | High8.6 | No fix yet |