cbcvebase.
CVE-2026-20129
published 2026-02-25

CVE-2026-20129: A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected…

PriorityP276critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.72%
49.5th percentile
A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. The vulnerability is due to improper authentication for requests that are sent to the API. An attacker could exploit this vulnerability by sending a crafted request to the API of an affected system. A successful exploit could allow the attacker to execute commands with the privileges of the netadmin role. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.

Affected

341 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocatalyst_sd-wan
ciscocatalyst_sd-wan_manager< 20.9.8.220.9.8.2
ciscocatalyst_sd-wan_manager
ciscocatalyst_sd-wan_manager>= 20.11 < 20.12.5.320.12.5.3
ciscocatalyst_sd-wan_manager>= 20.13 < 20.15.4.220.15.4.2
ciscocatalyst_sd-wan_manager>= 20.16 < 20.1820.18
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager
ciscocisco_catalyst_sd-wan_manager

Detection & IOCsextracted from sources · hover to see the quote

  • Detect unauthenticated crafted API requests targeting Cisco Catalyst SD-WAN Manager that result in netadmin role access — monitor for API calls from unauthenticated sources that successfully authenticate or return privileged session tokens
  • Flag any unauthenticated remote access to the Cisco Catalyst SD-WAN Manager API that results in netadmin-level command execution — the vulnerability is due to improper authentication for API requests
  • Track Cisco Bug IDs CSCws33583, CSCws33584, CSCws33585 for patch status and correlate with SD-WAN Manager versions below 20.18 in asset inventory
  • Classify the vulnerability under CWE-287 (Improper Authentication) and CWE-648 (Incorrect Use of Privileged APIs) for SIEM rule tagging and triage prioritization
  • ·Only Cisco Catalyst SD-WAN Manager releases prior to 20.18 are affected; version 20.18 and later are not vulnerable
  • ·A public exploit exists for CVE-2026-20129 (CVSS 9.8 CRITICAL); prioritize patching exposed SD-WAN Manager API endpoints immediately

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.