Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-infodis-SPuJBDCe Security Impact Rating: Medium CVE: CVE-2026-20294
CSIRTS triage
- What
- Insufficient access control on specific template types allows authenticated attackers to view unencrypted sensitive authentication credentials in logs.
- Who is affected
- Low-privileged authenticated users of Catalyst SD-WAN Manager can access logs containing cleartext credentials.
- Urgency
- Medium severity; information disclosure of authentication credentials enables further network compromise.
- Action
- Apply Cisco Catalyst SD-WAN Manager software updates; no workarounds available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Catalyst SD-WAN Manager
Get an email when a new Catalyst SD-WAN Manager advisory drops — max one per day, one-click unsubscribe.
Details
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-202940.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20294 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedCisco Products Multiple Vulnerabilitieshkcert
- high[NEW] [high] Cisco Catalyst SD-WAN Manager: Multiple Vulnerabilitiescert-bund
- mediumCVE-2026-20294: A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could a…nvd
- criticalCisco Advance Notification for Publication of August 5, 2026, Security Advisoriescisco-psirt
More from Cisco Security Advisories
- criticalCisco IOS XR Software Security Hardening Release: September 20262026-09-11
- criticalCisco Secure Firewall Management Center Software Authentication Bypass Vulnerability2026-09-09
- unknownCisco Advance Notification for Publication of September 16, 2026, Security Advisories2026-09-09
- highCisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability2026-09-08
- mediumCisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities2026-09-08