Junglewise Threat Intelligence

CVE-2026-20123: Cisco EPNM and Prime Infrastructure open redirect in web interface

CVE-2026-20123 · Severity: medium · CVSS 4.3 · Published 2026-02-04

Technologies: Cisco Prime Infrastructure, Cisco Evolved Programmable Network Manager. Vendors: Cisco.

Executive brief

Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure, which are used to manage and monitor large-scale network environments, contain a security flaw in their web management interface. An attacker could trick a legitimate user into clicking a modified link that redirects them to a malicious website. This could be used in phishing campaigns to steal user credentials or deliver malware by making the malicious site appear to be part of the trusted Cisco management console.

Technical details

An open redirect vulnerability (CWE-601) exists in the web-based management interface of Cisco EPNM and Cisco Prime Infrastructure due to improper input validation of HTTP request parameters. A remote, unauthenticated attacker can exploit this by convincing a user to follow a specially crafted link or by intercepting and modifying a user's HTTP request. Successful exploitation allows the attacker to redirect the victim to an arbitrary external URL. This vulnerability is addressed in Cisco EPNM version 8.1.1 and Cisco Prime Infrastructure 3.10.6 Security Update 2. No workarounds are available.

Affected products

  • Cisco Evolved Programmable Network Manager (EPNM) Versions prior to 8.1.1
  • Cisco Prime Infrastructure Versions prior to 3.10.6 Security Update 2

Timeline

  • 2026-02-04: advisory: Initial public release by Cisco
  • 2026-02-04: disclosed
  • 2026-02-04: patched

References

Related threats