CVE-2026-20189Disclosure(cisco / prime_infrastructure)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to download arbitrary log files from the server. This vulnerability is due to insufficient authorization checks on the download service API. An attacker could exploit this vulnerability by submitting a crafted URL request to an affected device. A successful exploit could allow the attacker to download sensitive log files that they would otherwise not have authorization to access. To exploit this vulnerability, the attacker must have valid credentials to access the web-based management interface of the affected device.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • prime_infrastructure

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
prime_infrastructure

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-06: 2Technical Details · 2026-05-06: 205-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-20189 A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to download arbitrary log file… https://www.cve.org/CVERecord?id=CVE-2026-20189 ----- Traducción: CVE-2026-20189 Una vuln… http://infoflow.cloud`

    Post summary

    The post announces a newly documented CVE affecting Cisco Prime Infrastructure’s log download feature, providing basic technical details but no exploitation or mitigation information.

    0000038
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20189 A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to download arbitrary log file… https://www.cve.org/CVERecord?id=CVE-2026-20189

    Post summary

    The text reports a newly disclosed vulnerability (CVE-2026-20189) in Cisco Prime Infrastructure’s log download feature, allowing authenticated remote attackers to retrieve arbitrary log files, with no PoC, exploit, or patch information provided.

    00000135
    57.4K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoprime_infrastructure---
Appciscoprime_infrastructure3.10.6--
Appciscoprime_infrastructure3.10.6--
Appciscoprime_infrastructure3.10.6--

Explore more