Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3683 articles · 153461 vulns · 36/41 feeds (7d)
← Back to list
4.3
CVE-2026-20189PATCHED
Cisco · Cisco Prime Infrastructure

Cisco Prime Infrastructure Information Disclosure Vulnerability

Description

A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to download arbitrary log files from the server. This vulnerability is due to insufficient authorization checks on the download service API. An attacker could exploit this vulnerability by submitting a crafted URL request to an affected device. A successful exploit could allow the attacker to download sensitive log files that they would otherwise not have authorization to access. To exploit this vulnerability, the attacker must have valid credentials to access the web-based management interface of the affected device.

Affected Products

VendorProductVersions
CiscoCisco Prime Infrastructure3.6.0, 3.7.0, 3.4.0, 3.3.0, 3.5.0, 3.2.0-FIPS, 3.8.0-FED, 3.9.0, 3.8.0, 3.10.0, 3.9.1, 3.8.1, 3.7.1, 3.5.1, 3.4.2, 3.3.1, 3.2.1, 3.2.2, 3.4.1, 3.10.2, 3.10.3, 3.10, 3.10.1, 3.7.1 Update 03, 3.7.1 Update 04, 3.7.1 Update 06, 3.7.1 Update 07, 3.8.1 Update 01, 3.8.1 Update 02, 3.8.1 Update 03, 3.8.1 Update 04, 3.9.1 Update 01, 3.9.1 Update 02, 3.9.1 Update 03, 3.9.1 Update 04, 3.10 Update 01, 3.4.2 Update 01, 3.6.0 Update 04, 3.6.0 Update 02, 3.6.0 Update 03, 3.6.0 Update 01, 3.5.1 Update 03, 3.5.1 Update 01, 3.5.1 Update 02, 3.7.0 Update 03, 3.8.0 Update 01, 3.8.0 Update 02, 3.7.1 Update 01, 3.7.1 Update 02, 3.7.1 Update 05, 3.9.0 Update 01, 3.3.0 Update 01, 3.4.1 Update 02, 3.4.1 Update 01, 3.5.0 Update 03, 3.5.0 Update 01, 3.5.0 Update 02, 3.10.4, 3.10.4 Update 01, 3.10.4 Update 02, 3.10.4 Update 03, 3.10.5, 3.10.6, 3.10.6 Update 01, 3.10.6 Update 02

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
cisprime infrastructurecert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-unauth-infodiscl-LFnLgmey

Related News (2 articles)

Tier B
BSI Advisories7d ago
[NEU] [niedrig] Cisco Prime Infrastructure: Schwachstelle ermöglicht Offenlegung von Informationen
→ No new info (linked only)
Tier C
VulDB8d ago
CVE-2026-20189 | Cisco Prime Infrastructure up to 3.10.6 Download Service API authorization (cisco-sa-pi-unauth-infodiscl-LFnLgmey)
→ No new info (linked only)
CVSS 3.14.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
3.10.6
CWECWE-862
PublishedMay 6, 2026
Last enriched8d agov2
Trending Score13
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-20182EXPKEV
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Trending: 153
HIGHCVE-2026-20185
Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vunerability
Trending: 16
HIGHCVE-2026-20167
Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability
Trending: 14
MEDIUMCVE-2026-20193
Cisco Identity Services Engine Authentication Bypass Vulnerability
Trending: 13
MEDIUMCVE-2026-20169
Cisco IoT Field Network Director Command Injection Vulnerability
Trending: 12

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 6, 2026
Discovered by ZDM
May 6, 2026
Updated: patchAvailable
May 6, 2026
Patch Available
May 6, 2026

Version History

v2
Last enriched 8d ago
v2Tier C8d ago

Updated patch available to version 3.10.6 and confirmed no exploit exists.

patchAvailable
via VulDB
v18d ago

Initial creation