CVE-2026-20133
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation

Overview

CVE-2026-20133 is an information disclosure vulnerability in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that allows unauthenticated, remote attackers to read sensitive information on affected systems. The vulnerability was first published on February 25, 2026, and is part of a broader advisory (cisco-sa-sdwan-authbp-qwCX8D4v) covering multiple SD-WAN flaws. Affected versions include releases prior to 20.9.8.2, 20.12.5.3 (or 20.12.6.1), 20.15.4.2, and 20.18.2.1. It carries a CVSS v3.1 base score of 7.5 (High) (Cisco Advisory, CISA KEV).

Technical details

The vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and stems from insufficient file system access restrictions in the Cisco Catalyst SD-WAN Manager API. An unauthenticated attacker can exploit this flaw by sending crafted HTTP requests to the API endpoint, bypassing access controls to read sensitive files on the underlying operating system — no credentials are required. The Cisco advisory notes the bug ID is CSCws33583, and the flaw was discovered internally by Arthur Vidineyev of Cisco's Advanced Security Initiatives Group (ASIG). Technical analysis from VulnCheck and Decryption Digest indicates this CVE can be chained with companion vulnerabilities (e.g., CVE-2026-20128, CVE-2026-20122) to achieve credential theft and further system compromise (Cisco Advisory, VulnCheck).

Impact

Successful exploitation allows an unauthenticated remote attacker to read sensitive files from the underlying operating system of the SD-WAN Manager, potentially exposing credentials, configuration data, and other confidential information. When chained with related vulnerabilities in the same advisory (CVE-2026-20128 for DCA credential theft, CVE-2026-20122 for arbitrary file overwrite, CVE-2026-20129 for authentication bypass), attackers can escalate from information disclosure to full system compromise, including root-level access. The vulnerability has been linked to ransomware-adjacent campaigns and is tracked as exploited in the wild by CISA, with the threat actor group UAT-8616 and the Behinder web shell malware family associated with exploitation activity (CISA KEV, Cisco Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Cisco Catalyst SD-WAN Manager instances using tools like Shodan or Censys, targeting versions prior to 20.9.8.2, 20.12.5.3, 20.15.4.2, or 20.18.2.1.
  2. API Access: Send an unauthenticated HTTP GET request to the SD-WAN Manager API endpoint that lacks proper file system access restrictions — no credentials are required for this step.
  3. Sensitive File Retrieval: Craft the API request to traverse or access restricted file paths on the underlying OS, such as credential files or configuration data (e.g., similar to the DCA credential file path /opt/data/containers/config/data-collection-agent/.dca exploited in the related CVE-2026-20128).
  4. Credential Harvesting: Extract credentials or configuration details from the retrieved files, enabling further lateral movement or privilege escalation.
  5. Chained Exploitation: Use harvested credentials or access to exploit companion vulnerabilities (e.g., CVE-2026-20129 for authentication bypass, CVE-2026-20122 for arbitrary file overwrite) to achieve root-level access or deploy web shells such as Behinder for persistent access (Cisco Advisory, VulnCheck).

Indicators of compromise

  • Logs: Review /var/log/nms/containers/service-proxy/serviceproxy-access.log for unexpected unauthenticated GET requests to sensitive API paths; cross-reference source IPs against known administrator addresses.
  • Logs (CVE-2026-20128 chain): Look for log entries referencing /reports/data/opt/data/containers/config/data-collection-agent/.dca from non-administrator IPs, e.g.: "GET /reports/data/opt/data/containers/config/data-collection-agent/.dca HTTP/1.1" 200
  • Logs (CVE-2026-20122 chain): Search for POST requests to /dataservice/smartLicensing/uploadAck and check vmanage-server.log for suspicious filenames being written, such as path traversal patterns (e.g., ../../../../../../../../../../../var/lib/wildfly/standalone/deployments/cmd.gz.war).
  • File System: Check for the presence of /cmd.gz/cmd.jsp or similar web shell files not present on a clean installation; any access to this endpoint is a confirmed IOC.
  • Logs (web shell): Look for POST requests to /cmd.gz/cmd.jsp in the service proxy access log: "POST /cmd.gz/cmd.jsp HTTP/1.1" 200
  • Network: Unusual outbound connections from the SD-WAN Manager to unknown external IPs; HTTP requests using automated tools (e.g., python-requests user-agent) from unexpected source IPs.
  • Process/Malware: Presence of Behinder web shell artifacts or related post-exploitation tooling on the SD-WAN Manager host (Cisco Advisory, CISA KEV).

Mitigation and workarounds

Cisco has released fixed software versions and confirms there are no workarounds available. Organizations should upgrade to the following minimum fixed releases based on their current branch: 20.9.8.2 (for 20.9.x), 20.12.5.3 or 20.12.6.1 (for 20.10–20.12.x), 20.15.4.2 (for 20.13–20.15.x), or 20.18.2.1 (for 20.16–20.18.x). Releases earlier than 20.9 should migrate to a supported fixed release. As hardening measures, Cisco recommends restricting API and management interface access to trusted hosts only, disabling HTTP for the web UI, enabling external log forwarding, and following the Cisco Catalyst SD-WAN Hardening Guide. CISA's Emergency Directive ED-26-03 and supplemental Hunt & Hardening Guidance provide additional federal agency-specific remediation steps (Cisco Advisory, CISA KEV).

Community reactions

Cisco's PSIRT updated the advisory on April 22, 2026 to confirm active exploitation of CVE-2026-20133, having previously (in March 2026) only confirmed exploitation of the companion CVEs (CVE-2026-20128 and CVE-2026-20122). CISA issued Emergency Directive ED-26-03 and added the vulnerability to the KEV catalog with an unusually short three-day federal remediation deadline, signaling high urgency. Tenable published an FAQ on the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities, attributing activity to the threat cluster UAT-8616 and noting over 10 threat groups targeting these flaws (Tenable FAQ). Security media including BleepingComputer, The Register, Cybersecurity Dive, and Help Net Security covered the KEV addition extensively, with commentary noting that security teams may be underestimating the broader threat posed by the SD-WAN vulnerability cluster (Cisco Advisory, VulnCheck).

Additional resources


SourceThis report was generated using AI

Related Cisco SD-WAN Catalyst Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20224HIGH8.6
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026
CVE-2026-20245HIGH7.8
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
YesYesJun 04, 2026
CVE-2026-20262MEDIUM6.5
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
YesYesJun 15, 2026
CVE-2026-20210MEDIUM5.4
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026
CVE-2026-20209MEDIUM5.4
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management