CVE-2026-20304
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation

Overview

CVE-2026-20304 is an improper access control vulnerability (CWE-284) in Cisco Catalyst SD-WAN Controller and Manager software, discovered through a comprehensive internal security review by the Cisco Catalyst SD-WAN engineering team. The vulnerability was disclosed on August 5, 2026, as part of a broader software hardening release addressing multiple internally discovered issues. It affects a wide range of Cisco Catalyst SD-WAN releases spanning versions 17.x through 26.x across both Controller and Manager components, covering all deployment types including On-Prem, Cloud-Pro, Cloud (Cisco Managed), and FedRAMP. The vulnerability carries a CVSS v3.1 base score of 9.9 (Critical) (Cisco Advisory, GitHub Advisory).

Technical details

The vulnerability is classified under CWE-284 (Improper Access Control), which encompasses authorization, authentication, privilege, and bypass weaknesses. The root cause involves inadequate enforcement of access control mechanisms within the Cisco Catalyst SD-WAN software stack, allowing an authenticated attacker with low-level privileges to bypass authorization controls and access resources or functions outside their permitted scope. The attack vector is network-based, requires low privileges, no user interaction, and results in a scope change — indicating that a successful exploit can impact components beyond the directly vulnerable system. The vulnerability was identified during internal security testing using existing processes as well as frontier AI models, and no public proof-of-concept or technical write-up has been released (Cisco Advisory).

Impact

Successful exploitation allows an authenticated attacker with low privileges to bypass authorization controls, gaining unauthorized access to sensitive data, modifying critical SD-WAN system configurations, and disrupting service availability across the SD-WAN infrastructure. The changed scope metric indicates that exploitation can affect components beyond the directly vulnerable SD-WAN system, raising the risk of lateral movement within enterprise network environments. All three CIA pillars — confidentiality, integrity, and availability — are rated High, reflecting the potential for complete compromise of affected SD-WAN deployments (Cisco Advisory, GitHub Advisory).

Exploitability

As of the time of disclosure, Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild, and no public proof-of-concept exploit exists (Cisco Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.25–0.27%, placing it in the 19th percentile for exploitation probability within 30 days (GitHub Advisory). No threat actor attribution has been reported. Detection is supported by Qualys (ID: 317869) and Nessus (ID: 333337).

Mitigation and workarounds

Cisco has released fixed software versions and confirms there are no workarounds available for this vulnerability. Customers should upgrade to the following minimum fixed releases based on their current SD-WAN version:

  • 20.9.x: Upgrade to 20.9.10
  • 20.10.x, 20.11.x, 20.12.x: Upgrade to 20.12.8.1
  • 20.13.x, 20.14.x, 20.15.x: Upgrade to 20.15.6
  • 20.16.x, 20.18.x: Upgrade to 20.18.4
  • 26.1.x: Upgrade to 26.1.2
  • Releases earlier than 20.9 should migrate to a supported fixed release.

Cisco SD-WAN Cloud (Cisco Managed) has been addressed in Release 20.15.602 with no user action required. As a defense-in-depth measure, restrict network access to SD-WAN management interfaces and implement network segmentation to limit potential lateral movement (Cisco Advisory).

Community reactions

The vulnerability received broad coverage from security media outlets including The Hacker News, SecurityWeek, GBHackers, CyberSecurityNews, and SOCRadar, primarily framing it as part of a significant Cisco SD-WAN hardening release addressing multiple critical flaws (The Hacker News, SecurityWeek). Government cybersecurity agencies including CISA (via its weekly bulletin SB26-222) and Singapore's CSA (Alert AL-2026-100) flagged the advisory for enterprise attention. Qualys published a dedicated threat protection blog covering CVE-2026-20304 alongside related SD-WAN CVEs. Community sentiment highlighted the unusually broad version impact range and the use of AI-assisted internal testing as a notable aspect of Cisco's disclosure. Cisco's official statement emphasized that the vulnerabilities were found internally and are not known to be actively exploited (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco SD-WAN Catalyst Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20304CRITICAL9.9
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026
CVE-2026-20303CRITICAL9.9
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026
CVE-2026-20310CRITICAL9.1
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026
CVE-2026-20312HIGH8.8
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026
CVE-2026-20313HIGH7.7
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management