CVE-2026-20123Disclosure(cisco / evolved_programmable_network_manager)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in the HTTP request. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • evolved_programmable_network_manager
  • prime_infrastructure

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
evolved_programmable_network_managerprime_infrastructure

1 version affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-09: 1Technical Details · 2026-02-09: 102-09
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Open Redirect Vulnerability (CVE-2026-20123) #Cisco #CVE202620123 #CyberSecurity https://www.systemtek.co.uk/?p=48288 https://t.co/kwgSZpfmgf

    Post summary

    The tweet announces the existence of CVE-2026-20123, an open‑redirect vulnerability in Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure, without providing any PoC, exploit, or patch details.

    0000054
    1.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoevolved_programmable_network_manager---
Appciscoprime_infrastructure---
Appciscoprime_infrastructure3.10.6--
Appciscoprime_infrastructure3.10.6--

Explore more