SB2026080554 - Cleartext transmission of sensitive information in Catalyst SD-WAN Manager (formerly SD-WAN vManage)



SB2026080554 - Cleartext transmission of sensitive information in Catalyst SD-WAN Manager (formerly SD-WAN vManage)

Published: August 5, 2026

Security Bulletin ID SB2026080554
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Cleartext transmission of sensitive information (CVE-ID: CVE-2026-20294)

CWE-ID: CWE-319 - Cleartext Transmission of Sensitive Information

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to insufficient access control enforcement in the web-based management interface when viewing logs on the local system or on a remote logging server. A remote user can view logs containing sensitive authentication credentials to disclose sensitive information.

The issue affects specific template types that are not included in the encryption allowlist.


Remediation

Install update from vendor's website.