Junglewise Threat Intelligence

CVE-2026-20108: Cisco Catalyst SD-WAN Manager XSS in web management interface

CVE-2026-20108 · Severity: medium · CVSS 5.4 · Published 2026-03-25

Technologies: Cisco Catalyst SD-WAN Manager. Vendors: Cisco.

Executive brief

Cisco Catalyst SD-WAN Manager, a centralized management platform for software-defined networks, contains a security flaw in its web interface. An attacker could trick a logged-in administrator into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the administrator's browser. This could lead to the theft of sensitive session information or unauthorized actions performed on behalf of the user.

Technical details

A stored or reflected cross-site scripting (XSS) vulnerability exists in the web-based management interface of Cisco Catalyst SD-WAN Manager (formerly vManage). The root cause is insufficient validation of user-supplied input. An attacker with low-privileged credentials can exploit this by persuading a targeted user to click a specially crafted link or visit a malicious page while authenticated to the manager. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to the disclosure of sensitive browser-based information or session hijacking. Cisco has released software updates to address this vulnerability; no workarounds are available.

Affected products

  • Cisco Catalyst SD-WAN Manager 20.12 through 20.12.5.2, 20.12.6, 20.13, 20.14, 20.15 through 20.15.4.1, 20.16, 20.18 through 20.18.1

Timeline

  • 2026-03-25: disclosed: Initial public release of Cisco advisory
  • 2026-03-25: patched: Fixed software releases made available by Cisco

References

Related threats