CVE-2026-20182 Details
Description
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks. A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
An authentication bypass vulnerability has been identified in Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart) and Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). This vulnerability allows an unauthenticated, remote attacker to bypass authentication and gain administrative privileges on the affected system. The issue arises from a malfunctioning peering authentication mechanism, which an attacker could exploit by sending crafted requests. Successful exploitation could enable the attacker to log in as a high-privileged, non-root user, access NETCONF, and manipulate network configurations for the SD-WAN fabric.
Cisco has released software updates to address this vulnerability. Customers should upgrade to the fixed software release indicated in the Cisco Security Advisory. For additional information on the upgrade process, customers can consult the Cisco Catalyst SD-WAN Upgrade Matrix or contact the Cisco Technical Assistance Center (TAC).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | May 14, 2026 | May 17, 2026 | Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco catalyst sd-wan manager | < 20.9.9.1 >= 20.10, < 20.12.5.4 >= 20.12.6, < 20.12.6.2 >= 20.13, < 20.15.4.4 >= 20.15.5, < 20.15.5.2 >= 20.16, < 20.18.2.2 >= 26.1, < 26.1.1.1 20.12.7 |
CPE
Remediation
| |
| cisco sd-wan vbond orchestrator | < 20.9.9.1 >= 20.10, < 20.12.5.4 >= 20.12.6, < 20.12.6.2 >= 20.13, < 20.15.4.4 >= 20.15.5, < 20.15.5.2 >= 20.16, < 20.18.2.2 >= 26.1, < 26.1.1.1 20.12.7 |
CPE
Remediation
| |
| cisco sd-wan vsmart controller | < 20.9.9.1 >= 20.10, < 20.12.5.4 >= 20.12.6, < 20.12.6.2 >= 20.13, < 20.15.4.4 >= 20.15.5, < 20.15.5.2 >= 20.16, < 20.18.2.2 >= 26.1, < 26.1.1.1 20.12.7 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | Modified Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | CVE Modified | [email protected] |
| May 15, 2026 | Initial Analysis | [email protected] |
| May 14, 2026 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 14, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | New CVE Received | [email protected] |