CVE-2026-20129
published 2026-02-25CVE-2026-20129: A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected…
PriorityP276critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.72%
49.5th percentile
A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role.
The vulnerability is due to improper authentication for requests that are sent to the API. An attacker could exploit this vulnerability by sending a crafted request to the API of an affected system. A successful exploit could allow the attacker to execute commands with the privileges of the netadmin role.
Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
Affected
341 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_sd-wan | — | — |
| cisco | catalyst_sd-wan_manager | < 20.9.8.2 | 20.9.8.2 |
| cisco | catalyst_sd-wan_manager | — | — |
| cisco | catalyst_sd-wan_manager | >= 20.11 < 20.12.5.3 | 20.12.5.3 |
| cisco | catalyst_sd-wan_manager | >= 20.13 < 20.15.4.2 | 20.15.4.2 |
| cisco | catalyst_sd-wan_manager | >= 20.16 < 20.18 | 20.18 |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect unauthenticated crafted API requests targeting Cisco Catalyst SD-WAN Manager that result in netadmin role access — monitor for API calls from unauthenticated sources that successfully authenticate or return privileged session tokens ↗
- →Flag any unauthenticated remote access to the Cisco Catalyst SD-WAN Manager API that results in netadmin-level command execution — the vulnerability is due to improper authentication for API requests ↗
- →Track Cisco Bug IDs CSCws33583, CSCws33584, CSCws33585 for patch status and correlate with SD-WAN Manager versions below 20.18 in asset inventory ↗
- →Classify the vulnerability under CWE-287 (Improper Authentication) and CWE-648 (Incorrect Use of Privileged APIs) for SIEM rule tagging and triage prioritization ↗
- ·Only Cisco Catalyst SD-WAN Manager releases prior to 20.18 are affected; version 20.18 and later are not vulnerable ↗
- ·A public exploit exists for CVE-2026-20129 (CVSS 9.8 CRITICAL); prioritize patching exposed SD-WAN Manager API endpoints immediately ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Catalyst SD-WAN Vulnerabilities
vendor_cisco·2026-02-26·CVSS 9.8
CVE-2026-20122 [CRITICAL] CWE-200 Cisco Catalyst SD-WAN Vulnerabilities
Cisco Catalyst SD-WAN Vulnerabilities
Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an attacker to access an affected system, elevate privileges to root, gain access to sensitive information, and overwrite arbitrary files.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
Cisco strongly recommends that customers upgrade to the fixed software indicated in this advisory.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v
Cisco
Cisco Catalyst SD-WAN Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2026-20129 Cisco Catalyst SD-WAN Vulnerabilities
CVE-2026-20129: Cisco Catalyst SD-WAN Vulnerabilities
Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an attacker to access an affected system, elevate privileges to root, gain access to sensitive information, and overwrite arbitrary files. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-200, CWE-257, CWE-287, CWE-200, CWE-257, CWE-287, CWE-648, CWE-200, CWE-257, CWE-287, CWE-200, CWE-257, CWE-287, CWE-648
Bug IDs: CSCws33583, CSCws33584, CSCws33585, CSCws33583, CSCws33584
GHSA
GHSA-5h54-2f2f-5x5c: A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an a
ghsa_unreviewed·2026-02-25
CVE-2026-20129 [CRITICAL] CWE-287 GHSA-5h54-2f2f-5x5c: A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an a
A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role.
The vulnerability is due to improper authentication for requests that are sent to the API. An attacker could exploit this vulnerability by sending a crafted request to the API of an affected system. A successful exploit could allow the attacker to execute commands with the privileges of the netadmin role.
Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-20128 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 10.0
CVE-2026-20128 [CRITICAL] CVE-2026-20128 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20128 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system.
This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges.
Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
Source : NVD
## 7.5
Score
Published Febr
Wiz
CVE-2026-20129 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-20129 [MEDIUM] CVE-2026-20129 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20129 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role.
The vulnerability is due to improper authentication for requests that are sent to the API. An attacker could exploit this vulnerability by sending a crafted request to the API of an affected system. A successful exploit could allow the attacker to execute commands with the privileges of the netadmin role.
Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
Source : NVD
## 9.8
Score
Published February 25, 2026
Severity CRITICAL
CNA Score 9.8
Affe
Wiz
CVE-2026-20133 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-20133 [MEDIUM] CVE-2026-20133 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20133 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive information on an affected system.
This vulnerability is due to insufficient file system access restrictions. An attacker could exploit this vulnerability by accessing the API of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.
Source : NVD
## 7.5
Score
Published February 25, 2026
Severity HIGH
CNA Score 6.5
Affected Technologies
Cisco SD-WAN Catalyst Manager
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EP
Wiz
CVE-2026-20108 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-20108 [MEDIUM] CVE-2026-20108 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20108 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of the web-based management interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Source : NVD
## 5.4
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologi
Wiz
CVE-2026-20126 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-20126 [MEDIUM] CVE-2026-20126 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20126 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system.
This vulnerability is due to an insufficient user authentication mechanism in the REST API. An attacker could exploit this vulnerability by sending a request to the REST API of the affected system. A successful exploit could allow the attacker to gain root privileges on the underlying operating system.
Source : NVD
## 7.8
Score
Published February 25, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Cisco SD-WAN Catalyst Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Du
Wiz
CVE-2026-20122 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-20122 [MEDIUM] CVE-2026-20122 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20122 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system.
This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
Source : NVD
## 5.4
Score
Published February 25, 2026
Severity MEDIUM
CNA Score 5.4
Affe
Wiz
CVE-2026-20127 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 10.0
CVE-2026-20127 [CRITICAL] CVE-2026-20127 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20127 :
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker co
2026-02-25
Published