
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20304 is an improper access control vulnerability (CWE-284) in Cisco Catalyst SD-WAN Controller and Manager software, discovered through a comprehensive internal security review by the Cisco Catalyst SD-WAN engineering team. The vulnerability was disclosed on August 5, 2026, as part of a broader software hardening release addressing multiple internally discovered issues. It affects a wide range of Cisco Catalyst SD-WAN releases spanning versions 17.x through 26.x across both Controller and Manager components, covering all deployment types including On-Prem, Cloud-Pro, Cloud (Cisco Managed), and FedRAMP. The vulnerability carries a CVSS v3.1 base score of 9.9 (Critical) (Cisco Advisory, GitHub Advisory).
The vulnerability is classified under CWE-284 (Improper Access Control), which encompasses authorization, authentication, privilege, and bypass weaknesses. The root cause involves inadequate enforcement of access control mechanisms within the Cisco Catalyst SD-WAN software stack, allowing an authenticated attacker with low-level privileges to bypass authorization controls and access resources or functions outside their permitted scope. The attack vector is network-based, requires low privileges, no user interaction, and results in a scope change — indicating that a successful exploit can impact components beyond the directly vulnerable system. The vulnerability was identified during internal security testing using existing processes as well as frontier AI models, and no public proof-of-concept or technical write-up has been released (Cisco Advisory).
Successful exploitation allows an authenticated attacker with low privileges to bypass authorization controls, gaining unauthorized access to sensitive data, modifying critical SD-WAN system configurations, and disrupting service availability across the SD-WAN infrastructure. The changed scope metric indicates that exploitation can affect components beyond the directly vulnerable SD-WAN system, raising the risk of lateral movement within enterprise network environments. All three CIA pillars — confidentiality, integrity, and availability — are rated High, reflecting the potential for complete compromise of affected SD-WAN deployments (Cisco Advisory, GitHub Advisory).
As of the time of disclosure, Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild, and no public proof-of-concept exploit exists (Cisco Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.25–0.27%, placing it in the 19th percentile for exploitation probability within 30 days (GitHub Advisory). No threat actor attribution has been reported. Detection is supported by Qualys (ID: 317869) and Nessus (ID: 333337).
Cisco has released fixed software versions and confirms there are no workarounds available for this vulnerability. Customers should upgrade to the following minimum fixed releases based on their current SD-WAN version:
Cisco SD-WAN Cloud (Cisco Managed) has been addressed in Release 20.15.602 with no user action required. As a defense-in-depth measure, restrict network access to SD-WAN management interfaces and implement network segmentation to limit potential lateral movement (Cisco Advisory).
The vulnerability received broad coverage from security media outlets including The Hacker News, SecurityWeek, GBHackers, CyberSecurityNews, and SOCRadar, primarily framing it as part of a significant Cisco SD-WAN hardening release addressing multiple critical flaws (The Hacker News, SecurityWeek). Government cybersecurity agencies including CISA (via its weekly bulletin SB26-222) and Singapore's CSA (Alert AL-2026-100) flagged the advisory for enterprise attention. Qualys published a dedicated threat protection blog covering CVE-2026-20304 alongside related SD-WAN CVEs. Community sentiment highlighted the unusually broad version impact range and the use of AI-assisted internal testing as a notable aspect of Cisco's disclosure. Cisco's official statement emphasized that the vulnerabilities were found internally and are not known to be actively exploited (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."