
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20129 is a critical authentication bypass vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). It allows an unauthenticated, remote attacker to gain access to an affected system with the privileges of the netadmin role. The vulnerability was discovered internally by Arthur Vidineyev of Cisco's Advanced Security Initiatives Group (ASIG) and publicly disclosed on February 25, 2026. Affected versions include releases from 20.9 through 20.17 (prior to their respective fixed releases); Cisco Catalyst SD-WAN Manager 20.18 and later are not affected. It carries a CVSS v3.1 base score of 9.8 (Critical) (Cisco Advisory).
The root cause is improper authentication (CWE-287) for requests sent to the Cisco Catalyst SD-WAN Manager API. The vulnerability exists because the API does not properly validate or enforce authentication for certain request types, allowing a remote, unauthenticated attacker to craft a specially formed API request that bypasses authentication controls entirely. No user interaction or prior privileges are required, and the attack is conducted entirely over the network. The vulnerability is tracked under Cisco Bug ID CSCws33587 and is part of a broader advisory covering multiple SD-WAN Manager flaws (Cisco Advisory).
Successful exploitation grants an unauthenticated remote attacker the ability to execute commands with netadmin role privileges on the affected Cisco Catalyst SD-WAN Manager system, resulting in high confidentiality, integrity, and availability impact. An attacker with netadmin access can manipulate SD-WAN network configurations, potentially disrupting WAN connectivity across an enterprise, exfiltrating sensitive network topology and credential data, and using the foothold for lateral movement to connected SD-WAN edge devices and other network infrastructure. The scope of impact is significant given that SD-WAN Manager serves as the centralized management plane for enterprise WAN environments (Cisco Advisory, Feedly).
netadmin role user.netadmin role privileges, enabling execution of privileged API commands without valid credentials.netadmin session to enumerate network configurations, modify SD-WAN policies, extract credentials or sensitive data, or chain with other vulnerabilities (e.g., CVE-2026-20122 for arbitrary file overwrite) to achieve deeper system compromise or deploy web shells (Cisco Advisory)./var/log/nms/containers/service-proxy/serviceproxy-access.log for unexpected API requests from unknown or untrusted IP addresses, particularly requests to sensitive API endpoints without corresponding legitimate administrator activity.netadmin-level operations.GET /reports/data/opt/data/containers/config/data-collection-agent/.dca from non-administrator IPs in serviceproxy-access.log.POST /dataservice/smartLicensing/uploadAck from unexpected IPs; check vmanage-server.log for suspicious filenames being written (e.g., path traversal patterns like ../../../../../../../../../../../var/lib/wildfly/standalone/deployments/cmd.gz.war)./cmd.gz/cmd.jsp or similar web shell files not present on a clean installation.serviceproxy-access.log referencing POST /cmd.gz/cmd.jsp or similar non-standard endpoints.python-requests user-agent) from non-administrator sources (Cisco Advisory).Cisco has released fixed software versions and confirms there are no workarounds available for CVE-2026-20129. Organizations should upgrade to the following fixed releases as soon as possible:
As interim hardening measures, Cisco recommends restricting SD-WAN Manager API access to known, trusted hosts via firewall rules, disabling HTTP access to the management portal, placing the system behind a filtering device, and monitoring API authentication logs for anomalous activity. Cisco strongly recommends upgrading to a fixed release rather than relying on network controls alone (Cisco Advisory).
The broader Cisco Catalyst SD-WAN Manager advisory (which includes CVE-2026-20129) received significant attention from the security community following Cisco's confirmation of active exploitation of related vulnerabilities in March 2026. Multiple outlets including The Hacker News, GovInfoSecurity, CyberScoop, and CyberSecurityNews covered the active exploitation of the SD-WAN Manager flaws, with headlines noting a "hacker free-for-all" over the SD-WAN vulnerabilities (GovInfoSecurity, The Hacker News). CERT-EU, the Australian Cyber Security Centre, CIS, and the Belgian Centre for Cybersecurity all issued advisories urging immediate patching (CERT-EU, ACSC, CIS). VulnCheck published a technical blog analyzing the SD-WAN Manager vulnerabilities, and Greenbone noted active exploitation against critical infrastructure (VulnCheck).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."