CVE-2026-20210
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation

Overview

CVE-2026-20210 is a privilege escalation vulnerability in the web UI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that allows an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions. The root cause is a failure to redact sensitive information within device configurations and templates, enabling low-privileged users to elevate to high-privileged access. It was first published on May 14, 2026, and affects Cisco Catalyst SD-WAN Manager across all deployment types (On-Prem, Cloud-Pro, Cloud Managed, and FedRAMP). It carries a CVSS v3.1 base score of 5.4 (Medium) (Cisco Advisory, Github Advisory).

Technical details

The vulnerability is classified under CWE-779 (Logging of Excessive Data), where sensitive information — specifically credentials or session tokens embedded in device configurations and templates — is not properly redacted in the web UI. An authenticated attacker with read-only access can retrieve this unredacted sensitive data and leverage it to assume the identity or session of a high-privileged user, effectively escalating their privileges without requiring additional authentication steps. The attack vector is network-based, requires low privileges (a valid read-only account), no user interaction, and has low attack complexity. The vulnerability was reported by Elise Imison of Computacenter and tracked as Cisco Bug ID CSCwt38767 (Cisco Advisory).

Impact

Successful exploitation allows an authenticated attacker with minimal (read-only) access to escalate privileges to those of a high-privileged administrator within Cisco Catalyst SD-WAN Manager, enabling unauthorized modification of device configurations and templates across the SD-WAN fabric. This could result in unauthorized network configuration changes, exposure of sensitive configuration data (low confidentiality impact), and integrity compromise of SD-WAN policies and device settings. Availability is not directly impacted, but configuration tampering could indirectly disrupt network operations across the SD-WAN deployment (Cisco Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify Cisco Catalyst SD-WAN Manager instances accessible via the web UI, targeting deployments where low-privileged (read-only) user accounts exist. Tools like Shodan or Censys can identify internet-exposed SD-WAN Manager portals.
  2. Authenticate as read-only user: Log in to the Cisco Catalyst SD-WAN Manager web UI using a valid read-only account (e.g., an operator-level credential obtained through phishing, credential stuffing, or insider access).
  3. Access device configurations and templates: Navigate to device configuration or template sections within the web UI that expose unredacted sensitive information — such as credentials, API tokens, or session identifiers embedded in configurations.
  4. Extract sensitive data: Retrieve the unredacted sensitive information from the device configurations or templates displayed in the web UI, which the system fails to properly mask for low-privileged users.
  5. Escalate privileges: Use the extracted sensitive information (e.g., admin credentials or session tokens) to authenticate or act as a high-privileged user within Cisco Catalyst SD-WAN Manager.
  6. Perform unauthorized actions: With elevated privileges, modify network configurations, device templates, or SD-WAN policies across the fabric (Cisco Advisory).

Indicators of compromise

  • Logs: Review Cisco Catalyst SD-WAN Manager audit logs for read-only user accounts performing configuration modification actions that exceed their expected permissions; look for unexpected privilege-level changes or admin-level API calls originating from low-privileged user sessions.
  • Logs: Monitor web UI access logs for read-only accounts accessing device configuration or template endpoints that are typically restricted to high-privileged users.
  • Network: Unexpected configuration change events or template modifications initiated from sessions associated with operator/read-only accounts.
  • Behavioral: Read-only user accounts performing actions such as pushing device configurations, modifying templates, or accessing sensitive credential fields in the SD-WAN Manager UI (Cisco Advisory).

Mitigation and workarounds

Cisco has released fixed software versions to address CVE-2026-20210. Customers should upgrade to the following minimum fixed releases based on their current version: 20.9.9.1 (for 20.9.x), 20.12.5.4 / 20.12.6.2 / 20.12.7.1 (for 20.12.x), 20.15.4.4 / 20.15.5.2 (for 20.15.x), 20.18.2.2 (for 20.18.x), and 26.1.1.1 (for 26.1.x). Cisco confirms there are no workarounds available for this vulnerability. As general hardening measures, Cisco recommends restricting web UI access to trusted hosts only, placing SD-WAN Manager behind a firewall, disabling HTTP access, and implementing least-privilege user account policies (Cisco Advisory).

Community reactions

The vulnerability was disclosed as part of a broader Cisco SD-WAN advisory bundle on May 14, 2026, which also included a Critical-rated XXE vulnerability (CVE-2026-20224) and a related privilege escalation issue (CVE-2026-20209). Media coverage focused primarily on the more severe CVE-2026-20127 authentication bypass (a separate advisory), which was reported as actively exploited, drawing attention to the overall security posture of Cisco SD-WAN infrastructure. Security outlets including Heise and HelpNetSecurity covered the broader SD-WAN advisory wave, and the Belgian Centre for Cybersecurity issued a warning about authentication bypass risks in Cisco Catalyst SD-WAN (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco SD-WAN Catalyst Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20224HIGH8.6
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026
CVE-2026-20245HIGH7.8
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
YesYesJun 04, 2026
CVE-2026-20262MEDIUM6.5
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
YesYesJun 15, 2026
CVE-2026-20210MEDIUM5.4
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026
CVE-2026-20209MEDIUM5.4
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management