---
id: CVE-2026-20123
title: "A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.\r\n\r\nThis…"
summary: "A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.\r\n\r\nThis…"
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-601
vendor: cisco
product: evolved_programmable_network_manager
affected:
  - evolved_programmable_network_manager < 8.1.1
  - prime_infrastructure < 3.10.6
  - prime_infrastructure = 3.10.6
patched:
  - evolved_programmable_network_manager 8.1.1
  - prime_infrastructure 3.10.6
published: '2026-02-04'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20123'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-epnm-pi-redirect-6sX82dN
    label: psirt@cisco.com
tags:
  - nvd
epss: 0.00191
epssPercentile: 0.09063
ingestedAt: '2026-06-29T21:48:47.237Z'
---

## Overview

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.

This vulnerability is due to improper input validation of the parameters in the HTTP request. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page.

## Affected

- `evolved_programmable_network_manager < 8.1.1`
- `prime_infrastructure < 3.10.6`
- `prime_infrastructure = 3.10.6`

## Remediation

Upgrade past the affected range:

- `evolved_programmable_network_manager 8.1.1`
- `prime_infrastructure 3.10.6`
