Cleartext transmission of sensitive information in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20294
Published: August 5, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to insufficient access control enforcement in the web-based management interface when viewing logs on the local system or on a remote logging server. A remote user can view logs containing sensitive authentication credentials to disclose sensitive information.
The issue affects specific template types that are not included in the encryption allowlist.