CVE-2026-20133

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file

Severity
Medium 6.5
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Apr 20, 2026
EPSS
0.314
98.1th percentile
Discovered by
Vendor
Published by the vendor
Published
Feb 25, 2026
Assigned by cisco

Description

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.

Weakness: CWE-200

Affected products

Vendor Product Category Matched by
Cisco Cisco Catalyst SD-WAN Manager Network & Security Management cna-assigner
Vendor-reported affected versions (1)
  • Cisco · Cisco Catalyst SD-WAN Manager