CVE-2026-20129

Cisco Catayst SD-WAN Authentication Bypass Vulnerability

Severity
Critical 9.8
CVSS 3.1
Exploited
Not listed
EPSS
0.007
50.3th percentile
Discovered by
Vendor
Published by the vendor
Published
Feb 25, 2026
Assigned by cisco

Description

A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. The vulnerability is due to improper authentication for requests that are sent to the API. An attacker could exploit this vulnerability by sending a crafted request to the API of an affected system. A successful exploit could allow the attacker to execute commands with the privileges of the netadmin role. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability. 

Weakness: CWE-287

Affected products

Vendor Product Category Matched by
Cisco Cisco Catalyst SD-WAN Manager Network & Security Management cna-assigner
Vendor-reported affected versions (1)
  • Cisco · Cisco Catalyst SD-WAN Manager