CVE-2026-20209
EUVD-2026-3032714.05.2026, 17:16
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user. This vulnerability exists because sensitive session information is recorded in audit logs. An attacker could exploit this vulnerability by elevating their read-only permissions in Cisco Catalyst SD-WAN Manager to those of a high-privileged user. A successful exploit could allow the attacker to perform actions as a high-privileged user.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cisco | catalyst_sd-wan_manager | 𝑥 < 20.9.9.1 |
| cisco | catalyst_sd-wan_manager | 20.10 ≤ 𝑥 < 20.12.5.4 |
| cisco | catalyst_sd-wan_manager | 20.12.6 ≤ 𝑥 < 20.12.6.2 |
| cisco | catalyst_sd-wan_manager | 20.13 ≤ 𝑥 < 20.15.4.4 |
| cisco | catalyst_sd-wan_manager | 20.15.5 ≤ 𝑥 < 20.15.5.2 |
| cisco | catalyst_sd-wan_manager | 20.16 ≤ 𝑥 < 20.18.2.2 |
| cisco | catalyst_sd-wan_manager | 26.1 ≤ 𝑥 < 26.1.1.1 |
| cisco | catalyst_sd-wan_manager | 20.12.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration