Cleartext transmission of sensitive information in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20294

 

Cleartext transmission of sensitive information in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20294

Published: August 5, 2026


Vulnerability identifier: #VU141010
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20294
CWE-ID: CWE-319
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to insufficient access control enforcement in the web-based management interface when viewing logs on the local system or on a remote logging server. A remote user can view logs containing sensitive authentication credentials to disclose sensitive information.

The issue affects specific template types that are not included in the encryption allowlist.


Affected software

Catalyst SD-WAN Manager (formerly SD-WAN vManage)

How to mitigate CVE-2026-20294

Install security update from vendor's website.

Catalyst SD-WAN Manager (formerly SD-WAN vManage) - addressed in versions 20.9.10, 20.12.8, 20.15.6, 20.18.4, 26.1.2, 26.2.1

External References

Related Security Bulletins