← Back

CVE-2026-20209

nvd nist
Published: May 14, 2026Modified: Jun 29, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: psirt@cisco.com (Secondary)

Description

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user. This vulnerability exists because sensitive session information is recorded in audit logs. An attacker could exploit this vulnerability by elevating their read-only permissions in Cisco Catalyst SD-WAN Manager to those of a high-privileged user. A successful exploit could allow the attacker to perform actions as a high-privileged user.

Affected (8)

1 product
Catalyst Sd Wan Manager
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Before 20.9.9.1
From 20.10 to 20.12.5.4
From 20.12.6 to 20.12.6.2
From 20.13 to 20.15.4.4
From 20.15.5 to 20.15.5.2
From 20.16 to 20.18.2.2
From 26.1 to 26.1.1.1
Version 20.12.7

Timeline

No history available yet.