Information disclosure in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20210

 

Information disclosure in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20210

Published: May 14, 2026


Vulnerability identifier: #VU131453
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20210
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify configurations and perform unauthorized actions.

The vulnerability exists due to improper redaction of sensitive information in device configurations and templates in the web UI when exposing configuration data. A remote user can leverage exposed sensitive information to modify configurations and perform unauthorized actions.

The issue requires read-only permissions.


Affected software

Catalyst SD-WAN Manager (formerly SD-WAN vManage)

How to mitigate CVE-2026-20210

Install security update from vendor's website.

Catalyst SD-WAN Manager (formerly SD-WAN vManage) - addressed in versions 20.15.4.3, 20.15.5.1, 20.18.2.2, 26.1.1

External References

Related Security Bulletins