Improper access control in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20304

 

Improper access control in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20304

Published: August 6, 2026


Vulnerability identifier: #VU141020
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20304
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass access restrictions and compromise the system.

The vulnerability exists due to improper access control in Catalyst SD-WAN Manager when processing authorization- or authentication-related operations. A remote user can perform crafted actions to bypass access restrictions and compromise the system.

This CVE groups multiple internally discovered issues in the improper access control class, including authorization, authentication, privilege, and bypass weaknesses.


Affected software

Catalyst SD-WAN Manager (formerly SD-WAN vManage)

How to mitigate CVE-2026-20304

Install security update from vendor's website.

Catalyst SD-WAN Manager (formerly SD-WAN vManage) - addressed in versions 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, 26.1.2

External References

Related Security Bulletins