Inclusion of Sensitive Information in Log Files in Cisco RoomOS - CVE-2026-20289

 

Inclusion of Sensitive Information in Log Files in Cisco RoomOS - CVE-2026-20289

Published: August 6, 2026


Vulnerability identifier: #VU141056
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20289
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to insertion of sensitive information into log files in the logging subsystem when extended logging is enabled and system logs are collected. A remote user can enable a specific logging level and collect the system logs to disclose sensitive information.

User interaction is required.


Affected software

Cisco RoomOS

How to mitigate CVE-2026-20289

Install security update from vendor's website.

Cisco RoomOS - update to 26.7.2.2

External References

Related Security Bulletins