CVE-2026-20127 Details
Description
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
An authentication bypass vulnerability has been identified in Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager. This vulnerability allows an unauthenticated, remote attacker to bypass authentication and gain administrative privileges on the affected system. The issue arises because the peering authentication mechanism is not functioning correctly. Exploitation involves sending crafted requests to the system, which could enable the attacker to log in as a high-privileged, non-root user. With this access, the attacker could utilize NETCONF to manipulate network configurations within the SD-WAN fabric.
Cisco has released software updates to address this vulnerability. Affected users should upgrade to the latest version of Cisco Catalyst SD-WAN Software. For specific upgrade instructions, consult the Cisco Catalyst SD-WAN Upgrade Matrix or the Cisco Product Security Incident Response Team (PSIRT) guidance.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20127 | CISA-ADP | US Government Resource |
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk | [email protected] | Vendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability | Feb 25, 2026 | Feb 27, 2026 | Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco catalyst sd-wan manager | < 20.9.8.2 >= 20.11, < 20.12.5.3 >= 20.13, < 20.15.4.2 >= 20.16, < 20.18.2.1 20.12.6 |
CPE
Remediation
| |
| cisco sd-wan vbond orchestrator | < 20.9.8.2 >= 20.11, < 20.12.5.3 >= 20.13, < 20.15.4.2 >= 20.16, < 20.18.2.1 20.12.6 |
CPE
Remediation
| |
| cisco sd-wan vsmart controller | < 20.9.8.2 >= 20.11, < 20.12.5.3 >= 20.13, < 20.15.4.2 >= 20.16, < 20.18.2.1 20.12.6 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | Modified Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | CVE Modified | [email protected] |
| Feb 26, 2026 | Initial Analysis | [email protected] |
| Feb 25, 2026 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Feb 25, 2026 | CVE Modified | CISA-ADP |
| Feb 25, 2026 | New CVE Received | [email protected] |