CVE-2026-20129

A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. The vulnerability is due to improper authentication for requests that are sent to the API. An attacker could exploit this vulnerability by sending a crafted request to the API of an affected system. A successful exploit could allow the attacker to execute commands with the privileges of the netadmin role. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability. 
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:catalyst_sd-wan_manager:20.12.6:*:*:*:*:*:*:*

History

17 Jun 2026, 10:17

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en la autenticación de usuarios de la API de Cisco Catalyst SD-WAN Manager podría permitir a un atacante remoto no autenticado obtener acceso a un sistema afectado como un usuario con el rol de netadmin. La vulnerabilidad se debe a una autenticación incorrecta para las solicitudes que se envían a la API. Un atacante podría explotar esta vulnerabilidad enviando una solicitud manipulada a la API de un sistema afectado. Un exploit exitoso podría permitir al atacante ejecutar comandos con los privilegios del rol de netadmin. Nota: Las versiones 20.18 y posteriores de Cisco Catalyst SD-WAN Manager no se ven afectadas por esta vulnerabilidad.

04 Mar 2026, 21:16

Type Values Removed Values Added
CPE cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:catalyst_sd-wan_manager:20.12.6:*:*:*:*:*:*:*
First Time Cisco
Cisco catalyst Sd-wan Manager
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v - () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v - Vendor Advisory

25 Feb 2026, 17:25

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 17:25

Updated : 2026-06-17 10:17


NVD link : CVE-2026-20129

Mitre link : CVE-2026-20129

CVE.ORG link : CVE-2026-20129


JSON object : View

Products Affected

cisco

  • catalyst_sd-wan_manager
CWE
CWE-287

Improper Authentication