CVE-2026-20209Disclosure(cisco / catalyst_sd-wan_manager)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user. This vulnerability exists because sensitive session information is recorded in audit logs. An attacker could exploit this vulnerability by elevating their read-only permissions in Cisco Catalyst SD-WAN Manager to those of a high-privileged user. A successful exploit could allow the attacker to perform actions as a high-privileged user.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-779

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • catalyst_sd-wan_manager

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
catalyst_sd-wan_manager

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-14: 1Mentions · 2026-05-17: 1Technical Details · 2026-05-14: 105-1405-17
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW 『(直訳)Cisco Catalyst SD-WAN Controller(旧称:SD-WAN vSmart)およびCisco Catalyst SD-WAN Manager(旧称:SD-WAN vManage)のピアリング認証における脆弱性により、認証されていないリモート攻撃者が認証を回避し、影響を受けるシステム上で管理者権限を取得できる可能性があります』 CVE-2026-20209/CVE-2026-20210/CVE-2026-20224 Cisco Catalyst SD-WAN Manager Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R 『(直訳)Cisco Catalyst SD-WAN Manager(旧称:SD-WAN vManage)には複数の脆弱性が存在し、リモートの攻撃者が機密情報にアクセスしたり、権限を昇格させたり、アプリケーションへの不正アクセスを実行したりする可能性があります。』

    Post summary

    The text announces Cisco SD‑WAN Controller and Manager vulnerabilities that allow unauthenticated remote attackers to bypass authentication and potentially gain administrator privileges, referencing official Cisco security advisories.

    01010825
    11.6K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-20209 | Cisco Catalyst SD-WAN Manager up to 26.0.1 Web UI logging of excessive data (cisco-sa-sdwan-mltvnps2-JxpWm7R / WID-SEC-2026-1540) https://ift.tt/0YPlwxi A vulnerability identified as critical has been detected in Cisco Catalyst SD-WAN Manager. Affected by this…

    Post summary

    The post announces a critical vulnerability (CVE‑2026‑20209) affecting Cisco Catalyst SD‑WAN Manager up to 26.0.1, describing excessive data logging in the Web UI, but offers no further technical or mitigation details.

    0000049
    974 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appciscocatalyst_sd-wan_manager---
Appciscocatalyst_sd-wan_manager20.12.7--

Explore more