CVE-2026-20133
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file
Severity
Medium 6.5
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Apr 20, 2026
EPSS
0.314
98.1th percentile
Discovered by
Vendor
Published by the vendor
Published
Feb 25, 2026
Assigned by cisco
Description
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.
Weakness: CWE-200
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Catalyst SD-WAN Manager | Network & Security Management | cna-assigner |
Vendor-reported affected versions (1)
- Cisco · Cisco Catalyst SD-WAN Manager