CVE-2026-20126
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation

Overview

CVE-2026-20126 is a privilege escalation vulnerability in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that allows an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. It was discovered internally by Arthur Vidineyev of the Cisco Advanced Security Initiatives Group (ASIG) and publicly disclosed on February 25, 2026. Affected versions include releases prior to 20.9.8.2, 20.11.x through 20.12.5.3, 20.13.x through 20.15.4.2, and 20.16.x through 20.18.2.1; additionally, version 20.12.6 is specifically listed as affected. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Cisco Advisory).

Technical details

The root cause is classified as CWE-648 (Incorrect Use of Privileged APIs) — specifically, an insufficient user authentication mechanism in the Cisco Catalyst SD-WAN Manager REST API. An attacker who already holds a low-privilege local account can craft and send a specially formed request to the REST API, which fails to properly validate the caller's authorization level before executing privileged operations. This flaw allows the attacker to invoke privileged API functions that should be restricted to higher-privilege roles, ultimately resulting in root-level access on the underlying OS. No public proof-of-concept code has been confirmed for this specific CVE, and Cisco PSIRT has stated it is not aware of malicious use of CVE-2026-20126 specifically (Cisco Advisory).

Impact

Successful exploitation grants the attacker complete root access to the Cisco Catalyst SD-WAN Manager system, enabling arbitrary command execution, modification of system configurations, and access to all sensitive data on the host. Because SD-WAN Manager serves as the centralized control plane for SD-WAN fabric, a compromised instance could allow an attacker to pivot to connected SD-WAN edge devices and broader network infrastructure. All three pillars — confidentiality, integrity, and availability — are fully impacted (Cisco Advisory, Feedly).

Exploitation steps

  1. Gain low-privilege access: Obtain valid credentials for a low-privilege local account on the Cisco Catalyst SD-WAN Manager system (e.g., through credential theft, phishing, or reuse of compromised credentials).
  2. Authenticate to the REST API: Use the low-privilege credentials to authenticate to the SD-WAN Manager REST API endpoint.
  3. Craft a privileged REST API request: Construct a specially crafted HTTP request targeting a REST API endpoint that improperly validates user authentication, exploiting the insufficient authorization check (CWE-648).
  4. Send the malicious request: Submit the crafted request to the REST API of the affected system. The API fails to enforce proper privilege boundaries, allowing the low-privilege user to invoke privileged operations.
  5. Achieve root privileges: The successful exploit results in the attacker gaining root-level privileges on the underlying operating system, enabling arbitrary command execution, configuration changes, and lateral movement to connected SD-WAN infrastructure (Cisco Advisory).

Indicators of compromise

  • Logs: Review /var/log/nms/containers/service-proxy/serviceproxy-access.log for anomalous REST API requests originating from unexpected source IPs or at unusual times, particularly requests that should require elevated privileges but are issued by low-privilege accounts.
  • Logs: Monitor /var/log/nms/vmanage-server.log for unexpected file operations, path traversal patterns, or references to suspicious filenames being written or downloaded (relevant to the broader advisory exploitation chain).
  • File System: Check for the presence of unexpected files such as /cmd.gz/cmd.jsp or other web shells in the SD-WAN Manager deployment directories, which may indicate chained exploitation with related CVEs in the same advisory.
  • Process: Look for unusual processes spawned with root privileges from the SD-WAN Manager application context, such as unexpected shell processes or network utilities.
  • Network: Monitor for unexpected outbound connections from the SD-WAN Manager host to external IPs, which may indicate post-exploitation activity or data exfiltration (Cisco Advisory).

Mitigation and workarounds

Cisco has released fixed software versions and confirms there are no workarounds available for CVE-2026-20126. Organizations should upgrade to the following fixed releases: 20.9.8.2 (for 20.9.x), 20.12.5.3 or 20.12.6.1 (for 20.11.x/20.12.x), 20.15.4.2 (for 20.13.x/20.14.x/20.15.x), and 20.18.2.1 (for 20.16.x/20.18.x). As hardening measures, Cisco recommends restricting REST API access to known, trusted management hosts via firewall rules, disabling HTTP for the web UI, sending logs to an external server, and applying the principle of least privilege to all user accounts (Cisco Advisory).

Community reactions

The broader Cisco Catalyst SD-WAN advisory (cisco-sa-sdwan-authbp-qwCX8D4v), which includes CVE-2026-20126 alongside four other CVEs, received significant industry attention due to confirmed active exploitation of related vulnerabilities (CVE-2026-20128 and CVE-2026-20122) in March 2026. CERT/EU, the Australian Cyber Security Centre (ACSC), CIS, and Belgium's CCB all issued advisories referencing the vulnerability cluster (CERT EU, ACSC, CIS Advisory). The Hacker News and multiple security outlets covered Cisco's confirmation of active exploitation, and VulnCheck published a technical analysis of the SD-WAN Manager vulnerability set (VulnCheck Blog, The Hacker News). Social media discussion on Mastodon and Bluesky highlighted the severity of the advisory cluster, with researchers noting the risk of chained exploitation across the related CVEs.

Additional resources


SourceThis report was generated using AI

Related Cisco SD-WAN Catalyst Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20224HIGH8.6
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026
CVE-2026-20245HIGH7.8
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
YesYesJun 04, 2026
CVE-2026-20262MEDIUM6.5
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
YesYesJun 15, 2026
CVE-2026-20210MEDIUM5.4
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026
CVE-2026-20209MEDIUM5.4
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management