CVE-2026-20155 is a high-severity (CVSS 8.0) improper authorization vulnerability affecting the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM). An authenticated, low-privileged remote attacker can exploit a REST API endpoint to access sensitive session information, including that of administrative users. This could lead to the compromise of the affected device due to the high confidentiality, integrity, and availability impact. There is currently no evidence of active exploitation, nor is public exploit code available in common repositories. However, the vulnerability has been noted in community discussions, indicating some awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.1.2CPE matchmatch criteria | cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.