Junglewise Threat Intelligence

CVE-2026-20155: Cisco EPNM improper authorization in REST API

CVE-2026-20155 · Severity: high · CVSS 8 · Published 2026-04-01

Technologies: Cisco Evolved Programmable Network Manager. Vendors: Cisco.

Executive brief

Cisco Evolved Programmable Network Manager (EPNM) is a management platform used by service providers to manage complex network infrastructures. A security flaw in its web interface allows a user with low-level access to view sensitive session information belonging to other active users, including administrators. This could allow an attacker to hijack administrative sessions and gain full control over the management platform and the network it oversees.

Technical details

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) is caused by improper authorization checks on a specific REST API endpoint (CWE-862). An authenticated, remote attacker with low privileges can exploit this by sending a crafted query to the affected endpoint. Successful exploitation allows the attacker to view session information for active users, including those with administrative privileges. This information can be leveraged to compromise the device or hijack sessions. Cisco has released software updates to address this issue; no workarounds are available.

Affected products

  • Cisco Evolved Programmable Network Manager (EPNM) < 8.1.2

Timeline

  • 2026-04-01: advisory: Initial public release by Cisco
  • 2026-04-01: patched: Fixed in version 8.1.2

References

Related threats