CVE-2026-20209
published 2026-05-14CVE-2026-20209: A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only…
PriorityP432medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.19%
9.4th percentile
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user.
This vulnerability exists because sensitive session information is recorded in audit logs. An attacker could exploit this vulnerability by elevating their read-only permissions in Cisco Catalyst SD-WAN Manager to those of a high-privileged user. A successful exploit could allow the attacker to perform actions as a high-privileged user.
Affected
362 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_sd-wan_manager | < 20.9.9.1 | 20.9.9.1 |
| cisco | catalyst_sd-wan_manager | — | — |
| cisco | catalyst_sd-wan_manager | >= 20.10 < 20.12.5.4 | 20.12.5.4 |
| cisco | catalyst_sd-wan_manager | >= 20.12.6 < 20.12.6.2 | 20.12.6.2 |
| cisco | catalyst_sd-wan_manager | >= 20.13 < 20.15.4.4 | 20.15.4.4 |
| cisco | catalyst_sd-wan_manager | >= 20.15.5 < 20.15.5.2 | 20.15.5.2 |
| cisco | catalyst_sd-wan_manager | >= 20.16 < 20.18.2.2 | 20.18.2.2 |
| cisco | catalyst_sd-wan_manager | >= 26.1 < 26.1.1.1 | 26.1.1.1 |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
| cisco | cisco_catalyst_sd-wan_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f8xf-95r6-r95h: A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only
ghsa_unreviewed·2026-05-14
CVE-2026-20209 [MEDIUM] CWE-779 GHSA-f8xf-95r6-r95h: A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user.
This vulnerability exists because sensitive session information is recorded in audit logs. An attacker could exploit this vulnerability by elevating their read-only permissions in Cisco Catalyst SD-WAN Manager to those of a high-privileged user. A successful exploit could allow the attacker to perform actions as a high-privileged user.
VulDB
Cisco Catalyst SD-WAN Manager up to 26.0.1 Web UI logging of excessive data (cisco-sa-sdwan-mltvnps2-JxpWm7R)
vuldb·2026-05-14·CVSS 5.4
CVE-2026-20209 [MEDIUM] Cisco Catalyst SD-WAN Manager up to 26.0.1 Web UI logging of excessive data (cisco-sa-sdwan-mltvnps2-JxpWm7R)
A vulnerability identified as critical has been detected in Cisco Catalyst SD-WAN Manager. Affected by this issue is some unknown functionality of the component Web UI. This manipulation causes logging of excessive data.
This vulnerability is registered as CVE-2026-20209. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-14
Published