Improper authentication in Cisco Systems, Inc products - CVE-2026-20182
Published: May 14, 2026
Catalyst SD-WAN Manager (formerly SD-WAN vManage)
Cisco SD-WAN vEdge Routers
Catalyst SD-WAN Controller (formerly SD-WAN vSmart)
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication and obtain administrative privileges.
The vulnerability exists due to improper authentication in the peering authentication mechanism when handling control connection handshaking requests. A remote attacker can send crafted requests to bypass authentication and obtain administrative privileges.
A successful exploit could allow access as an internal, high-privileged, non-root user account and subsequent access to NETCONF to manipulate SD-WAN fabric configuration.
Note, the vulnerability is being actively exploited in the wild.