
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20210 is a privilege escalation vulnerability in the web UI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that allows an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions. The root cause is a failure to redact sensitive information within device configurations and templates, enabling low-privileged users to elevate to high-privileged access. It was first published on May 14, 2026, and affects Cisco Catalyst SD-WAN Manager across all deployment types (On-Prem, Cloud-Pro, Cloud Managed, and FedRAMP). It carries a CVSS v3.1 base score of 5.4 (Medium) (Cisco Advisory, Github Advisory).
The vulnerability is classified under CWE-779 (Logging of Excessive Data), where sensitive information — specifically credentials or session tokens embedded in device configurations and templates — is not properly redacted in the web UI. An authenticated attacker with read-only access can retrieve this unredacted sensitive data and leverage it to assume the identity or session of a high-privileged user, effectively escalating their privileges without requiring additional authentication steps. The attack vector is network-based, requires low privileges (a valid read-only account), no user interaction, and has low attack complexity. The vulnerability was reported by Elise Imison of Computacenter and tracked as Cisco Bug ID CSCwt38767 (Cisco Advisory).
Successful exploitation allows an authenticated attacker with minimal (read-only) access to escalate privileges to those of a high-privileged administrator within Cisco Catalyst SD-WAN Manager, enabling unauthorized modification of device configurations and templates across the SD-WAN fabric. This could result in unauthorized network configuration changes, exposure of sensitive configuration data (low confidentiality impact), and integrity compromise of SD-WAN policies and device settings. Availability is not directly impacted, but configuration tampering could indirectly disrupt network operations across the SD-WAN deployment (Cisco Advisory, Feedly).
Cisco has released fixed software versions to address CVE-2026-20210. Customers should upgrade to the following minimum fixed releases based on their current version: 20.9.9.1 (for 20.9.x), 20.12.5.4 / 20.12.6.2 / 20.12.7.1 (for 20.12.x), 20.15.4.4 / 20.15.5.2 (for 20.15.x), 20.18.2.2 (for 20.18.x), and 26.1.1.1 (for 26.1.x). Cisco confirms there are no workarounds available for this vulnerability. As general hardening measures, Cisco recommends restricting web UI access to trusted hosts only, placing SD-WAN Manager behind a firewall, disabling HTTP access, and implementing least-privilege user account policies (Cisco Advisory).
The vulnerability was disclosed as part of a broader Cisco SD-WAN advisory bundle on May 14, 2026, which also included a Critical-rated XXE vulnerability (CVE-2026-20224) and a related privilege escalation issue (CVE-2026-20209). Media coverage focused primarily on the more severe CVE-2026-20127 authentication bypass (a separate advisory), which was reported as actively exploited, drawing attention to the overall security posture of Cisco SD-WAN infrastructure. Security outlets including Heise and HelpNetSecurity covered the broader SD-WAN advisory wave, and the Belgian Centre for Cybersecurity issued a warning about authentication bypass risks in Cisco Catalyst SD-WAN (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."