CVE-2026-20123 describes an open redirect vulnerability in the web-based management interfaces of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure. This medium-severity flaw (CVSS 4.3) stems from improper input validation, allowing an unauthenticated, remote attacker to redirect users to malicious web pages by intercepting and modifying HTTP requests. While the vulnerability has a FAUCET Risk Score of 73/100, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Community discussion and media coverage are minimal, with only one mention and one article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.1.1CPE matchmatch criteria | cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:* | ||
< 3.10.6CPE matchmatch criteria | cpe:2.3:a:cisco:prime_infrastructure:*:-:*:*:*:*:*:* | ||
3.10.6CPE matchmatch criteria | cpe:2.3:a:cisco:prime_infrastructure:3.10.6:-:*:*:*:*:*:* | ||
3.10.6CPE matchmatch criteria | cpe:2.3:a:cisco:prime_infrastructure:3.10.6:security_update_01:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.