Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20158 are related to improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
Published: 2026-07-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper control of a resource throughout its lifetime can allow an attacker to interfere with resource allocation, use, or deallocation, which may cause exhaustion of system resources or grant unauthorized access. The weakness is classified under CWE‑664.

Affected Systems

Cisco RoomOS software is affected. No specific product versions are listed by the CNA; therefore, all installations of Cisco RoomOS that have not yet received the hardening release remain at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity; the EPSS score is less than 1%, suggesting a low likelihood of exploitation in the wild at this time. This vulnerability is not listed in CISA KEV, implying no known widespread exploitation. Based on the description, it is inferred that the attack vector could involve local or privileged access, though the exact path of exploitation is not disclosed.

Generated by OpenCVE AI on August 3, 2026 at 03:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Cisco RoomOS to the latest security hardening release that contains the fix for this vulnerability.
  • Disable or restrict any functions that expose unnecessary resource lifetimes or are no longer required.
  • Monitor system logs for abnormal resource allocation or deallocation events to detect potential abuse or misconfiguration.

Generated by OpenCVE AI on August 3, 2026 at 03:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco roomos Software
Vendors & Products Cisco
Cisco roomos Software

Wed, 15 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20158 are related to improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
Title Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulnerabilities
Weaknesses CWE-664
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Cisco Roomos Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-07-15T18:07:02.708Z

Reserved: 2025-10-08T11:59:15.387Z

Link: CVE-2026-20158

cve-icon Vulnrichment

Updated: 2026-07-15T18:06:54.566Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:15:05Z

Weaknesses
  • CWE-664

    Improper Control of a Resource Through its Lifetime