CVE Watchtower

← Back to CVE List

CVE-2026-20209NVD

Vulnerability Summary

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user.

This vulnerability exists because sensitive session information is recorded in audit logs. An attacker could exploit this vulnerability by elevating their read-only permissions in Cisco Catalyst SD-WAN Manager to those of a high-privileged user. A successful exploit could allow the attacker to perform actions as a high-privileged user.
Severity Level
MEDIUM(5.4)
Published Date
May 14, 2026
Last Modified
Jun 29, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.19%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics — Score 5.4 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityNone

Affected & Patched Versions

Affected Versions
  • Cisco Catalyst Sd-wan Manager < 20.9.9.1
  • Cisco Catalyst Sd-wan Manager >= 20.10 and < 20.12.5.4
  • Cisco Catalyst Sd-wan Manager >= 20.12.6 and < 20.12.6.2
  • Cisco Catalyst Sd-wan Manager >= 20.13 and < 20.15.4.4
  • Cisco Catalyst Sd-wan Manager >= 20.15.5 and < 20.15.5.2
  • Cisco Catalyst Sd-wan Manager >= 20.16 and < 20.18.2.2
  • Cisco Catalyst Sd-wan Manager >= 26.1 and < 26.1.1.1
  • Cisco Catalyst Sd-wan Manager
Patched Versions
  • Cisco Catalyst Sd-wan Manager 20.9.9.1
  • Cisco Catalyst Sd-wan Manager 20.12.5.4
  • Cisco Catalyst Sd-wan Manager 20.12.6.2
  • Cisco Catalyst Sd-wan Manager 20.15.4.4
  • Cisco Catalyst Sd-wan Manager 20.15.5.2
  • Cisco Catalyst Sd-wan Manager 20.18.2.2
  • Cisco Catalyst Sd-wan Manager 26.1.1.1
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.