Junglewise Threat Intelligence

CVE-2026-20294: Cisco Catalyst SD-WAN Manager information disclosure in web interface

CVE-2026-20294 · Severity: medium · CVSS 6.5 · Published 2026-08-05

Technologies: Cisco Catalyst SD-WAN Manager. Vendors: Cisco.

Executive brief

Cisco Catalyst SD-WAN Manager is a network management platform used to configure and monitor software-defined wide-area networks. A vulnerability in its web-based management interface allows authenticated users with low privileges to view sensitive authentication credentials and other confidential information in clear text by accessing logs, potentially enabling attackers to compromise connected network infrastructure and services.

Technical details

The vulnerability is an information disclosure issue (CWE-319) caused by insufficient access control enforcement for specific template types that are not included in the encryption allowlist in Cisco Catalyst SD-WAN Manager's web interface. A low-privileged, authenticated remote attacker can exploit this by viewing logs stored locally or on a remote logging server, exposing sensitive authentication credentials in clear text. No user interaction is required beyond authentication. The vulnerability affects all deployment types including on-premises, cloud-managed, and government deployments. Cisco has released patched versions across multiple release branches (e.g., 20.9.10, 20.12.8, 20.15.6, 20.18.4, 26.1.2, 26.2.1), and no workarounds are available.

Affected products

  • Cisco Catalyst SD-WAN Manager Before 20.9.10, 20.10–20.12.7, 20.13–20.15.5, 20.14–20.15.5, 20.16–20.18.3, 26.1–26.1.1, 26.2–26.2.0

Timeline

  • 2026-08-05: disclosed
  • 2026-08-05: patched: Patches released across multiple release branches
  • 2026-08-07: advisory: Advisory updated

References

Related threats