CVE-2026-20126 Details
Description
A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerability is due to an insufficient user authentication mechanism in the REST API. An attacker could exploit this vulnerability by sending a request to the REST API of the affected system. A successful exploit could allow the attacker to gain root privileges on the underlying operating system.
A vulnerability exists in Cisco Catalyst SD-WAN Manager that allows an authenticated, local attacker with low privileges to gain root access on the underlying operating system. This issue arises from an inadequate user authentication mechanism in the REST API, enabling attackers to exploit the vulnerability by sending requests that elevate their privileges.
Cisco has released software updates to address this vulnerability. Users are advised to upgrade to version 20.9.8.2 or later, or to consult the Cisco Catalyst SD-WAN Upgrade Matrix for guidance on upgrading from other versions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-648 | Incorrect Use of Privileged APIs | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco catalyst sd-wan manager | < 20.9.8.2 >= 20.11, < 20.12.5.3 >= 20.13, < 20.15.4.2 >= 20.16, < 20.18.2.1 20.12.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 4, 2026 | Initial Analysis | [email protected] |
| Feb 25, 2026 | New CVE Received | [email protected] |