CVE-2026-20210 Details
Description
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions on an affected system. This vulnerability exists because of a failure to redact sensitive information within device configurations and templates. An attacker could exploit this vulnerability by elevating their read-only permissions to those of a high-privileged user. A successful exploit could allow the attacker to access or modify configuration settings within Cisco Catalyst SD-WAN Manager as a high-privileged user.
A vulnerability exists in the web UI of Cisco Catalyst SD-WAN Manager that could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions. This issue arises from a failure to properly redact sensitive information in device configurations and templates, enabling attackers to elevate their permissions to those of a high-privileged user. Exploitation of this vulnerability could lead to unauthorized access or modification of configuration settings within Cisco Catalyst SD-WAN Manager as a high-privileged user.
Cisco has released software updates to address this vulnerability. Customers should upgrade to the latest version of Cisco Catalyst SD-WAN Software. For additional information, consult the Cisco Catalyst SD-WAN Upgrade Matrix or contact the Cisco Technical Assistance Center (TAC).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-779 | Logging of Excessive Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco catalyst sd-wan manager | < 20.9.9.1 >= 20.10, < 20.12.5.4 >= 20.12.6, < 20.12.6.2 >= 20.13, < 20.15.4.4 >= 20.15.5, < 20.15.5.2 >= 20.16, < 20.18.2.2 >= 26.1, < 26.1.1.1 20.12.7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | New CVE Received | [email protected] |