CVE-2026-20312
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation

Overview

CVE-2026-20312 is a cleartext storage of sensitive information vulnerability (CWE-312) affecting Cisco Catalyst SD-WAN Controller and Manager software across a wide range of versions. Discovered through Cisco's internal security review — including the use of frontier AI models — it was publicly disclosed on August 5, 2026, as part of a broader SD-WAN software hardening release. The vulnerability carries a CVSS v3.1 base score of 8.8 (High), affecting Cisco Catalyst SD-WAN Controller and Manager across dozens of versions from 17.x through 20.12.8 (Cisco Advisory, GitHub Advisory).

Technical details

The root cause is classified under CWE-312 (Cleartext Storage of Sensitive Information), meaning the Cisco Catalyst SD-WAN software stores sensitive data — such as credentials or configuration secrets — in plaintext within resources that may be accessible to other control spheres or lower-privileged users. An authenticated attacker with low-level privileges can access this sensitive data over the network without requiring user interaction or elevated permissions. The vulnerability affects all deployment types including On-Prem, SD-WAN Cloud-Pro, Cisco Managed Cloud, and FedRAMP deployments. No public proof-of-concept code has been identified (Cisco Advisory, GitHub Advisory).

Impact

Successful exploitation allows an authenticated low-privilege user to read sensitive information — including credentials and configuration data — stored in cleartext, resulting in high confidentiality, integrity, and availability impact per the CVSS scoring. Exposed credentials could enable lateral movement within the SD-WAN infrastructure, potentially allowing an attacker to escalate privileges, pivot to connected network segments, or compromise additional SD-WAN components such as controllers and edge devices. The broad scope of affected versions (17.x through 20.12.8) means a large number of enterprise and government SD-WAN deployments may be at risk (Cisco Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure. The Cisco PSIRT confirmed the vulnerabilities were found during internal security testing and are not known to be actively exploited. The EPSS score is approximately 0.187–0.198%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access with low privileges, which limits opportunistic exploitation but remains a meaningful risk in environments with insider threats or compromised low-privilege accounts (Cisco Advisory, GitHub Advisory).

Mitigation and workarounds

Cisco has released fixed software versions and strongly recommends upgrading immediately. There are no workarounds available for this vulnerability. The fixed releases by train are:

  • 20.9: Upgrade to 20.9.10
  • 20.10, 20.11: Upgrade to 20.12.8.1
  • 20.12: Upgrade to 20.12.8.1
  • 20.13, 20.14, 20.15: Upgrade to 20.15.6
  • 20.16, 20.18: Upgrade to 20.18.4
  • 26.1: Upgrade to 26.1.2
  • Releases earlier than 20.9 have reached End of Software Maintenance and must migrate to a supported fixed release.

Cisco SD-WAN Cloud (Cisco Managed) was addressed in Release 20.15.602 with no user action required. As a defense-in-depth measure, organizations should restrict authenticated user access to only necessary administrative interfaces and monitor for unauthorized access to configuration stores (Cisco Advisory).

Community reactions

Cisco's advisory was covered by multiple security news outlets including The Hacker News, SecurityWeek, GBHackers, CyberSecurityNews, and SOCRadar, primarily in the context of the broader August 2026 SD-WAN hardening release that addressed five CVEs simultaneously. Coverage highlighted that three of the five CVEs in the same advisory carried a near-maximum CVSS score of 9.9, drawing attention to the overall severity of the hardening release. AUSCERT and Singapore's CSA both issued bulletins referencing the advisory. Community sentiment noted the proactive nature of Cisco's internal discovery process, including the use of AI-assisted security testing (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco SD-WAN Catalyst Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20304CRITICAL9.9
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026
CVE-2026-20303CRITICAL9.9
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026
CVE-2026-20310CRITICAL9.1
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026
CVE-2026-20312HIGH8.8
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026
CVE-2026-20313HIGH7.7
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesAug 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management