Missing authorization in Evolved Programmable Network (EPN) Manager - CVE-2026-20155

 

Missing authorization in Evolved Programmable Network (EPN) Manager - CVE-2026-20155

Published: April 1, 2026


Vulnerability identifier: #VU124800
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20155
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to missing authorization checks in the REST API endpoint of an affected device. A remote authenticated user can send a specially crafted HTTP request and view session information of active Cisco EPNM users, including users with administrative privileges. Extracted session information can be used to login under administrative privileges and compromise the system. 


Affected software

Evolved Programmable Network (EPN) Manager

How to mitigate CVE-2026-20155

Install updates from vendor's website.

Evolved Programmable Network (EPN) Manager - update to 8.1.2

External References

Related Security Bulletins