Executive brief
Cisco Catalyst SD-WAN Manager is a network management platform used to configure and monitor software-defined wide-area networks. A vulnerability in its web-based management interface allows authenticated users with low privileges to view sensitive authentication credentials and other confidential information in clear text by accessing logs, potentially enabling attackers to compromise connected network infrastructure and services.
Technical details
The vulnerability is an information disclosure issue (CWE-319) caused by insufficient access control enforcement for specific template types that are not included in the encryption allowlist in Cisco Catalyst SD-WAN Manager's web interface. A low-privileged, authenticated remote attacker can exploit this by viewing logs stored locally or on a remote logging server, exposing sensitive authentication credentials in clear text. No user interaction is required beyond authentication. The vulnerability affects all deployment types including on-premises, cloud-managed, and government deployments. Cisco has released patched versions across multiple release branches (e.g., 20.9.10, 20.12.8, 20.15.6, 20.18.4, 26.1.2, 26.2.1), and no workarounds are available.
Affected products
- Cisco Catalyst SD-WAN Manager Before 20.9.10, 20.10–20.12.7, 20.13–20.15.5, 20.14–20.15.5, 20.16–20.18.3, 26.1–26.1.1, 26.2–26.2.0
Timeline
- 2026-08-05: disclosed
- 2026-08-05: patched: Patches released across multiple release branches
- 2026-08-07: advisory: Advisory updated