CVE-2026-20209

MEDIUM

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from lo...

Affects 0 products across 3 vendors.

BCS3.44
CVSS 3.15.4
EPSS0.2%
Percentile9th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, no availability impact.
CWE Weakness Definitions
CWE-779: CWE-779
◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager allows an authenticated, remote attacker with read-only permissions to elevate their privileges and perform actions as a high-privileged user.

BSID: BS-2026-GLOBAL-063256-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-20209?
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager allows an authenticated, remote attacker with read-only permissions to elevate their privileges and perform actions as a high-privileged user.
What is the CVSS score for CVE-2026-20209?
CVE-2026-20209 has CVSS 5.4 (Medium). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N. EPSS: 0.2%.
Is CVE-2026-20209 actively exploited?
No confirmed active exploitation of CVE-2026-20209 as of 2026-06-30.
How do I remediate CVE-2026-20209?
Priority: MEDIUM. Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R PSIRT: [email protected]
What systems are affected by CVE-2026-20209?
CVE-2026-20209 affects: Catalyst, Cisco, Francisco Burzi.
Vulnerability Details
CVE IDCVE-2026-20209
BSIDBS-2026-GLOBAL-063256-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Published2026-05-14
Last Modified2026-06-29
ICS Relevance55%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user. This vulnerability exists because sensitive session information is recorded in audit logs. An attacker could exploit this vulnerability by elevating their read-only permissions in Cisco Catalyst SD-WAN Manager to those of a high-privileged user. A successful exploit could allow the attacker to perform actions as a high-privileged user.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability exists because sensitive session information is recorded in audit logs. An attacker could exploit this by accessing the audit logs and using the sensitive information to elevate their privileges.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Catalyst —
Cisco —
Francisco Burzi —
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 72 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash8b16af2d770090268f0e1c8620f67604ac6ecc9f43da8004a6fa1cbdc328fce89886bede6234556191fed448c2e28a96279f7e12342ad327ce8949035110b952
Related CVEs affecting Catalyst
CVE-2026-26009 9.9 Catalyst is a platform built for enterprise game server hosts, game communiti... CVE-2025-20341 8.8 A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an aut... CVE-2026-20086 8.6 A vulnerability in the processing of Control and Provisioning of Wireless Acc... CVE-2026-20084 8.6 A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could a... CVE-2026-20224 8.6 A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-W...
View all Catalyst CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →