Junglewise Threat Intelligence

CVE-2026-20289: Cisco RoomOS information disclosure in logging subsystem

CVE-2026-20289 · Severity: medium · CVSS 5.7 · Published 2026-08-05

Technologies: Cisco RoomOS. Vendors: Cisco.

Executive brief

Cisco RoomOS is the software powering Cisco video conferencing and collaboration devices. A vulnerability in its logging system can expose sensitive information such as user login credentials to authenticated attackers who enable extended logging and access system logs. Extended logging is disabled by default, limiting the attack surface, but organizations with this feature enabled must upgrade to patch versions to prevent credential exposure.

Technical details

This vulnerability is a sensitive information disclosure (CWE-532) in the logging subsystem of Cisco RoomOS caused by improper logging of credentials and other sensitive data. An authenticated attacker with low privileges can exploit this by enabling extended logging (which must be manually activated) and then collecting or viewing system logs to extract user login credentials and other sensitive information. The attack requires user interaction (UI flag set) and network access to the device. Cisco has released fixed software versions addressing this vulnerability: RoomOS 11.39.1.3 or later for on-premises deployments, RoomOS 26.7.2.2 or later for cloud-aware deployments, and RoomOS June 2026 (26.7.1.12) or later for cloud deployments. No workarounds are available.

Affected products

  • Cisco RoomOS 11 and earlier, 26 and earlier

Timeline

  • 2026-08-05: disclosed

References

Related threats