Skip to content
CiscoCVE-2026-20289

Cisco RoomOS Software: information disclosure

Medium5.7CVE-2026-20289 · Published Aug 5, 2026 · updated Aug 17, 2026

A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials.

Cisco advisory

Affected versions

PackageAffectedFixed in
Cisco RoomOS Software
Product
<= RoomOS 10.11.2.2No fix yet
<= RoomOS 10.15.2.2No fix yet
<= RoomOS 11.5.4.6No fix yet
<= RoomOS 11.5.2.4No fix yet
Details and references

More Cisco advisories

All Cisco
Advisory
Cisco Catalyst SD-WAN: cleartext secrets
High8.8Aug 5
Cisco Catalyst SD-WAN: improper quantity validation
High7.7Aug 5
Cisco IOS XE Software: denial of service
Medium4.3Aug 5
Cisco Catalyst SD-WAN: link following
Critical9.1Aug 5
Cisco IOS XE Software: denial of service
Medium6.3Aug 5
Cisco IOS XE Software: denial of service
High8.6Aug 5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.