CISCO Security Advisory
Published Date: Not specified
CVE: CVE-2026-20294
Advisory Summary
ποΈ August 5, 2026
πβ¨ Cisco Catalyst SD-WAN Manager β Information Disclosure (CVE-2026-20294)
β¬οΈ What happened
A vulnerability exists in the web-based management interface of Cisco Catalyst SD-WAN Manager. An authenticated remote attacker could access sensitive information displayed in clear text.
π§© Root cause
Insufficient access control enforcement for certain template types that are missing from the encryption allowlist.
- View logs on the local system or a remote logging server
- Potentially retrieve sensitive authentication credentials
β οΈ Why it matters (security impact)
This is rated Medium, but the consequence can be high in practice: exposed authentication credentials may enable escalation and compromise of network infrastructure and connected services.
π§° Patches / mitigations
β
Cisco has released software updates that address the vulnerability.
π« No workarounds are available.
- Prioritize patching of affected Catalyst SD-WAN Manager releases immediately, especially in environments with external or semi-trusted access to the management plane.
- Verify encryption and access control behavior for template types involved in your deployment (and ensure youβre running the fixed software version).
- Review logging exposure paths:
- local log access controls
- remote syslog/log server permissions and transport protections
- Hunt for indicators of low-privileged users accessing log views/templates, and rotate credentials if any unauthorized access is suspected.
-WAN -2026-20294
Reference: Vendor Advisory