
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20126 is a privilege escalation vulnerability in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that allows an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. It was discovered internally by Arthur Vidineyev of the Cisco Advanced Security Initiatives Group (ASIG) and publicly disclosed on February 25, 2026. Affected versions include releases prior to 20.9.8.2, 20.11.x through 20.12.5.3, 20.13.x through 20.15.4.2, and 20.16.x through 20.18.2.1; additionally, version 20.12.6 is specifically listed as affected. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Cisco Advisory).
The root cause is classified as CWE-648 (Incorrect Use of Privileged APIs) — specifically, an insufficient user authentication mechanism in the Cisco Catalyst SD-WAN Manager REST API. An attacker who already holds a low-privilege local account can craft and send a specially formed request to the REST API, which fails to properly validate the caller's authorization level before executing privileged operations. This flaw allows the attacker to invoke privileged API functions that should be restricted to higher-privilege roles, ultimately resulting in root-level access on the underlying OS. No public proof-of-concept code has been confirmed for this specific CVE, and Cisco PSIRT has stated it is not aware of malicious use of CVE-2026-20126 specifically (Cisco Advisory).
Successful exploitation grants the attacker complete root access to the Cisco Catalyst SD-WAN Manager system, enabling arbitrary command execution, modification of system configurations, and access to all sensitive data on the host. Because SD-WAN Manager serves as the centralized control plane for SD-WAN fabric, a compromised instance could allow an attacker to pivot to connected SD-WAN edge devices and broader network infrastructure. All three pillars — confidentiality, integrity, and availability — are fully impacted (Cisco Advisory, Feedly).
/var/log/nms/containers/service-proxy/serviceproxy-access.log for anomalous REST API requests originating from unexpected source IPs or at unusual times, particularly requests that should require elevated privileges but are issued by low-privilege accounts./var/log/nms/vmanage-server.log for unexpected file operations, path traversal patterns, or references to suspicious filenames being written or downloaded (relevant to the broader advisory exploitation chain)./cmd.gz/cmd.jsp or other web shells in the SD-WAN Manager deployment directories, which may indicate chained exploitation with related CVEs in the same advisory.Cisco has released fixed software versions and confirms there are no workarounds available for CVE-2026-20126. Organizations should upgrade to the following fixed releases: 20.9.8.2 (for 20.9.x), 20.12.5.3 or 20.12.6.1 (for 20.11.x/20.12.x), 20.15.4.2 (for 20.13.x/20.14.x/20.15.x), and 20.18.2.1 (for 20.16.x/20.18.x). As hardening measures, Cisco recommends restricting REST API access to known, trusted management hosts via firewall rules, disabling HTTP for the web UI, sending logs to an external server, and applying the principle of least privilege to all user accounts (Cisco Advisory).
The broader Cisco Catalyst SD-WAN advisory (cisco-sa-sdwan-authbp-qwCX8D4v), which includes CVE-2026-20126 alongside four other CVEs, received significant industry attention due to confirmed active exploitation of related vulnerabilities (CVE-2026-20128 and CVE-2026-20122) in March 2026. CERT/EU, the Australian Cyber Security Centre (ACSC), CIS, and Belgium's CCB all issued advisories referencing the vulnerability cluster (CERT EU, ACSC, CIS Advisory). The Hacker News and multiple security outlets covered Cisco's confirmation of active exploitation, and VulnCheck published a technical analysis of the SD-WAN Manager vulnerability set (VulnCheck Blog, The Hacker News). Social media discussion on Mastodon and Bluesky highlighted the severity of the advisory cluster, with researchers noting the risk of chained exploitation across the related CVEs.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."