CVE-2026-20294
Received Received - Intake

Information Disclosure in Cisco Catalyst SD-WAN Manager

Vulnerability report for CVE-2026-20294, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
cisco catalyst_sd-wan_manager *
cisco catalyst_sd-wan_manager 20.9.10
cisco catalyst_sd-wan_manager 20.12.8
cisco catalyst_sd-wan_manager 20.15.6
cisco catalyst_sd-wan_manager 20.18.4
cisco catalyst_sd-wan_manager 26.1.2
cisco catalyst_sd-wan_manager 26.2.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an information disclosure flaw in Cisco Catalyst SD-WAN Manager's web-based management interface. It allows an authenticated remote attacker with low privileges to view sensitive information in clear text, such as authentication credentials, by accessing logs on the local system or a remote logging server. The issue occurs due to insufficient access control enforcement for specific template types not included in the encryption allowlist.

Detection Guidance

Detect this vulnerability by checking Cisco Catalyst SD-WAN Manager logs for exposed sensitive information. Review logs on the local system or remote logging servers for clear text authentication credentials. Ensure logs do not contain sensitive data from unencrypted template types.

Impact Analysis

An attacker could exploit this vulnerability to view sensitive authentication credentials, which may lead to further compromise of network infrastructure and connected services. This could result in unauthorized access, data breaches, or additional attacks on your systems.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive authentication credentials, which may violate data protection requirements under GDPR and HIPAA. Exposure of such data risks non-compliance with confidentiality and security controls mandated by these regulations.

Mitigation Strategies

Upgrade Cisco Catalyst SD-WAN Manager to fixed software releases like 20.9.10, 20.12.8, 20.15.6, 20.18.4, 26.1.2, or 26.2.1 based on your current version. No workarounds are available, so patching is required to address the insufficient access control enforcement.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20294. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart