SB2026080554 - Cleartext transmission of sensitive information in Catalyst SD-WAN Manager (formerly SD-WAN vManage)
Published: August 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Cleartext transmission of sensitive information (CVE-ID: CVE-2026-20294)
CWE-ID: CWE-319 - Cleartext Transmission of Sensitive Information
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to insufficient access control enforcement in the web-based management interface when viewing logs on the local system or on a remote logging server. A remote user can view logs containing sensitive authentication credentials to disclose sensitive information.
The issue affects specific template types that are not included in the encryption allowlist.
Remediation
Install update from vendor's website.