SB2026080610 - Multiple vulnerabilities in Cisco Catalyst SD-WAN software



SB2026080610 - Multiple vulnerabilities in Cisco Catalyst SD-WAN software

Published: August 6, 2026

Security Bulletin ID SB2026080610
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Input validation error (CVE-ID: CVE-2026-20303)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code, access files outside intended paths, or otherwise compromise the system.

The vulnerability exists due to improper input validation in Catalyst SD-WAN Manager when handling crafted input. A remote user can send specially crafted input to execute arbitrary code, access files outside intended paths, or otherwise compromise the system.

This CVE groups multiple internally discovered issues in the improper input validation class, including path traversal and external path control cases.


2) Improper access control (CVE-ID: CVE-2026-20304)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass access restrictions and compromise the system.

The vulnerability exists due to improper access control in Catalyst SD-WAN Manager when processing authorization- or authentication-related operations. A remote user can perform crafted actions to bypass access restrictions and compromise the system.

This CVE groups multiple internally discovered issues in the improper access control class, including authorization, authentication, privilege, and bypass weaknesses.


3) Link following (CVE-ID: CVE-2026-20310)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to access or manipulate files through improper link resolution.

The vulnerability exists due to improper link resolution before file access in Catalyst SD-WAN Manager when accessing files through links. A remote user can create or use a crafted link to access or manipulate files through improper link resolution.

This CVE groups multiple internally discovered issues in the improper link resolution before file access class.


4) Cleartext storage of sensitive information (CVE-ID: CVE-2026-20312)

CWE-ID: CWE-312 - Cleartext Storage of Sensitive Information

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to cleartext storage of sensitive information in Catalyst SD-WAN Manager when storing sensitive data. A remote user can obtain access to stored cleartext data to disclose sensitive information.

This CVE groups multiple internally discovered issues in the cleartext storage of sensitive information class.


5) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-20313)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service or otherwise affect system integrity through malformed quantity values.

The vulnerability exists due to improper validation of specified quantity in input in Catalyst SD-WAN Manager when processing quantity values in input. A remote user can send specially crafted input containing malformed quantity values to cause a denial of service or otherwise affect system integrity through malformed quantity values.

This CVE groups multiple internally discovered issues in the improper validation of specified quantity in input class.


Remediation

Install update from vendor's website.