Improper access control in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20304
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to bypass access restrictions and compromise the system.
The vulnerability exists due to improper access control in Catalyst SD-WAN Manager when processing authorization- or authentication-related operations. A remote user can perform crafted actions to bypass access restrictions and compromise the system.
This CVE groups multiple internally discovered issues in the improper access control class, including authorization, authentication, privilege, and bypass weaknesses.