Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-infodis-SPuJBDCe Security Impact Rating: Medium CVE: CVE-2026-20294
CSIRTS triage
- What
- Insufficient access control on specific template types allows authenticated attackers to view unencrypted sensitive authentication credentials in logs.
- Who is affected
- Low-privileged authenticated users of Catalyst SD-WAN Manager can access logs containing cleartext credentials.
- Urgency
- Medium severity; information disclosure of authentication credentials enables further network compromise.
- Action
- Apply Cisco Catalyst SD-WAN Manager software updates; no workarounds available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Catalyst SD-WAN Manager
Get an email when a new Catalyst SD-WAN Manager advisory drops — max one per day, one-click unsubscribe.
Details
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-202940.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20294 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Cisco Catalyst SD-WAN Manager: Multiple Vulnerabilitiescert-bund
- mediumCVE-2026-20294: A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could a…nvd
- criticalCisco Advance Notification for Publication of August 5, 2026, Security Advisoriescisco-psirt
Recent advisories for Cisco Catalyst SD-WAN
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Cisco Catalyst SD-WAN Manager: Multiple Vulnerabilitiescert-bund · 2026-08-06
- unknownNCSC-2026-0277 [1.00] [M/H] Vulnerabilities patched in Cisco Catalyst SD-WANncsc-nl · 2026-08-06
- highCVE-2026-20313: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd · 2026-08-05
- highCVE-2026-20312: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd · 2026-08-05
- criticalCVE-2026-20310: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd · 2026-08-05
- criticalCVE-2026-20304: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd · 2026-08-05
More from Cisco Security Advisories
- criticalCisco Advance Notification for Publication of August 5, 2026, Security Advisories2026-08-05
- highCisco Integrated Management Controller Argument Injection Vulnerabilities2026-08-05
- mediumCisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability2026-08-05
- mediumCisco Terminal Services Agent Firewall Rules Bypass Vulnerability2026-08-05
- mediumCisco RoomOS Logging Subsystem Information Disclosure Vulnerability2026-08-05