Junglewise Threat Intelligence

CVE-2026-20209: Cisco Catalyst SD-WAN Manager privilege escalation in web UI

CVE-2026-20209 · Severity: medium · CVSS 5.4 · Published 2026-05-14

Technologies: Cisco Catalyst SD-WAN Manager. Vendors: Cisco.

Executive brief

Cisco Catalyst SD-WAN Manager, a tool used to centrally manage and configure software-defined networks, contains a security flaw that could allow a user with limited access to gain full administrative control. This occurs because the system inadvertently records sensitive session data in its activity logs, which a low-privileged user can view. If exploited, an attacker could change network configurations, disrupt services, or access sensitive operational data.

Technical details

A privilege escalation vulnerability exists in the web UI of Cisco Catalyst SD-WAN Manager (formerly vManage) due to the logging of excessive data (CWE-779). The system records sensitive session information within audit logs that are accessible to users with read-only permissions. An authenticated, remote attacker with low privileges can extract this session data to impersonate a high-privileged user. Once elevated, the attacker can perform any action available to an administrator, including modifying device configurations and templates. Cisco has released software updates to address this issue; no workarounds are available.

Affected products

  • Cisco Catalyst SD-WAN Manager Earlier than 20.9, 20.9 before 20.9.9.1, 20.10 before 20.12.7.1, 20.11 before 20.12.7.1, 20.12 before 20.12.5.4, 20.13 before 20.15.5.2, 20.14 before 20.15.5.2, 20.15 before 20.15.4.4, 20.16 before 20.18.2.2, 26.1 before 26.1.1.1

Timeline

  • 2026-05-14: advisory: Initial publication by Cisco

References

Related threats