Cleartext storage of sensitive information in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20312

 

Cleartext storage of sensitive information in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20312

Published: August 6, 2026


Vulnerability identifier: #VU141022
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20312
CWE-ID: CWE-312
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to cleartext storage of sensitive information in Catalyst SD-WAN Manager when storing sensitive data. A remote user can obtain access to stored cleartext data to disclose sensitive information.

This CVE groups multiple internally discovered issues in the cleartext storage of sensitive information class.


Affected software

Catalyst SD-WAN Manager (formerly SD-WAN vManage)

How to mitigate CVE-2026-20312

Install security update from vendor's website.

Catalyst SD-WAN Manager (formerly SD-WAN vManage) - addressed in versions 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, 26.1.2

External References

Related Security Bulletins