Improper authentication in Cisco Systems, Inc products - CVE-2026-20182
Published: May 14, 2026 / Updated: May 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication and obtain administrative privileges.
The vulnerability exists due to improper authentication in the peering authentication mechanism when handling control connection handshaking requests. A remote attacker can send crafted requests to bypass authentication and obtain administrative privileges.
A successful exploit could allow access as an internal, high-privileged, non-root user account and subsequent access to NETCONF to manipulate SD-WAN fabric configuration.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Cisco SD-WAN vEdge Routers
Catalyst SD-WAN Controller (formerly SD-WAN vSmart)
How to mitigate CVE-2026-20182
Cisco SD-WAN vEdge Routers - addressed in versions 20.15.4.3, 20.15.5.1, 20.18.2.2, 26.1.1
Catalyst SD-WAN Controller (formerly SD-WAN vSmart) - addressed in versions 20.15.4.3, 20.15.5.1, 20.18.2.2, 26.1.1