Skip to content
CiscoCVE-2026-20294

Cisco Catalyst SD-WAN Manager: information disclosure

Medium6.5CVE-2026-20294 · Published Aug 5, 2026 · updated Aug 6, 2026

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services.

Cisco advisory

Affected versions

PackageAffectedFixed in
Cisco Catalyst SD-WAN Manager
Product
<= 20.1.12No fix yet
<= 19.2.1No fix yet
<= 18.4.4No fix yet
<= 18.4.5No fix yet
Details and references

More Cisco advisories

All Cisco
Advisory
Cisco Catalyst SD-WAN: cleartext secrets
High8.8Aug 5
Cisco Catalyst SD-WAN: improper quantity validation
High7.7Aug 5
Cisco IOS XE Software: denial of service
Medium4.3Aug 5
Cisco Catalyst SD-WAN: link following
Critical9.1Aug 5
Cisco IOS XE Software: denial of service
Medium6.3Aug 5
Cisco IOS XE Software: denial of service
High8.6Aug 5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.