CISCO Security Advisory
Published Date: Not specified
CVE: CVE-2026-20289
Advisory Summary
๐ August 05, 2026
๐ท๏ธ Cisco RoomOS Logging Subsystem Information Disclosure โ CVE-2026-20289 (Medium)
๐จ Whatโs happening?
Cisco reports an information disclosure weakness in the RoomOS logging subsystem. An authenticated local attacker with low privileges could abuse logging behavior to access sensitive data.
โ ๏ธ How it can be exploited (high level)
The issue stems from logging sensitive information. An attacker could:
1) enable a particular logging level, and
2) collect system logs,
potentially exposing sensitive details such as user login credentials.
- Impact: Exposure of sensitive information from logs
- Prerequisites: authenticated access + local access + low privilege
- Severity: Medium (per Ciscoโs advisory)
- Apply the released software updates that remediate the vulnerability.
- No workarounds are provided for this issue.
-2026-20289
Reference: Vendor Advisory