Executive brief
A critical vulnerability has been identified in Cisco's SD-WAN management and control components, which are used to orchestrate and secure corporate wide-area networks. An unauthenticated attacker can bypass security checks to gain administrative access to the network controller. This could allow an attacker to modify network configurations, potentially leading to data interception, network outages, or full control over the organization's SD-WAN fabric.
Technical details
A vulnerability in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller, Manager, and Validator (formerly vSmart, vManage, and vBond) allows for an authentication bypass. The flaw is rooted in improper handling of control connection handshaking, where the peering authentication mechanism fails to correctly validate identity. An unauthenticated, remote attacker can exploit this by sending crafted requests to an affected system. Successful exploitation allows the attacker to log in as a high-privileged, non-root user and access NETCONF, enabling full manipulation of the SD-WAN fabric configuration. Cisco has released software updates to address this issue; no workarounds are available.
Affected products
- Cisco Catalyst SD-WAN Controller (vSmart)
- Cisco Catalyst SD-WAN Manager (vManage)
- Cisco Catalyst SD-WAN Validator (vBond)
Timeline
- 2026-05-14: advisory: Initial publication of CVE-2026-20182
- 2026-05-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2026-06-16: other: Advisory updated to version 2.0 (Final)