Junglewise Threat Intelligence

CVE-2026-20210: Cisco Catalyst SD-WAN Manager privilege escalation in web UI

CVE-2026-20210 · Severity: medium · CVSS 5.4 · Published 2026-05-14

Technologies: Cisco Catalyst SD-WAN Manager. Vendors: Cisco.

Executive brief

Cisco Catalyst SD-WAN Manager is a centralized management platform used to configure and monitor corporate software-defined networks. A security flaw in its web interface allows a user with restricted, read-only access to view sensitive information that should have been hidden. An attacker can use this information to gain full administrative control, allowing them to change network settings or disrupt operations.

Technical details

A privilege escalation vulnerability exists in the web UI of Cisco Catalyst SD-WAN Manager (formerly vManage) due to a failure to properly redact sensitive information within device configurations and templates. An authenticated, remote attacker with low-privileged (read-only) access can exploit this by extracting sensitive data from these templates to elevate their permissions to those of a high-privileged user. Once elevated, the attacker can modify configuration settings and perform unauthorized administrative actions across the SD-WAN fabric. This issue is tracked as Cisco Bug ID CSCwt38767 and has been addressed in multiple software update trains including 20.9.9.1, 20.12.7.1, and 20.15.5.2.

Affected products

  • Cisco Catalyst SD-WAN Manager Earlier than 20.9, 20.9.9.1, 20.12.7.1, 20.15.5.2, 20.18.2.2, 26.1.1.1

Timeline

  • 2026-05-14: advisory: Initial advisory published by Cisco

References

Related threats