Executive brief
Cisco Catalyst SD-WAN Manager, a tool used to manage and monitor enterprise wide-area networks, contains a security flaw in its Data Collection Agent feature. An attacker can exploit this to obtain administrative credentials, potentially allowing them to take control of other systems within the SD-WAN infrastructure. This vulnerability has been observed being used in active attacks.
Technical details
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager (formerly vManage) stems from the storage of DCA user credentials in a recoverable format on the filesystem. While initially described as a local privilege escalation, updated advisory data indicates an unauthenticated, remote attacker can exploit this by sending a crafted HTTP request to read the credential file. Successful exploitation allows the attacker to retrieve the DCA password, which can be used to gain unauthorized privileges on the affected system or move laterally to other systems in the SD-WAN environment. This vulnerability is tracked as CWE-257 and is addressed in Cisco Catalyst SD-WAN Manager releases 20.18 and later.
Affected products
- Cisco Catalyst SD-WAN Manager Versions prior to 20.18
Timeline
- 2026-03-20: disclosed: Initial vendor disclosure
- 2026-04-20: advisory: NVD publication and CISA KEV addition
- 2026-04-20: exploited: Confirmed active exploitation in the wild per CISA KEV catalog