CVE-2026-20210

MEDIUM

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perfor...

Affects 0 products across 3 vendors.

BCS3.44
CVSS 3.15.4
EPSS0.2%
Percentile9th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, no availability impact.
CWE Weakness Definitions
CWE-779: CWE-779
◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager allows an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions due to a failure to redact sensitive information.

BSID: BS-2026-GLOBAL-063257-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-20210?
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager allows an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions due to a failure to redact sensitive information.
What is the CVSS score for CVE-2026-20210?
CVE-2026-20210 has CVSS 5.4 (Medium). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N. EPSS: 0.2%.
Is CVE-2026-20210 actively exploited?
No confirmed active exploitation of CVE-2026-20210 as of 2026-06-30.
How do I remediate CVE-2026-20210?
Priority: MEDIUM. Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R PSIRT: [email protected]
What systems are affected by CVE-2026-20210?
CVE-2026-20210 affects: Catalyst, Cisco, Francisco Burzi.
Vulnerability Details
CVE IDCVE-2026-20210
BSIDBS-2026-GLOBAL-063257-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Published2026-05-14
Last Modified2026-06-29
ICS Relevance55%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions on an affected system. This vulnerability exists because of a failure to redact sensitive information within device configurations and templates. An attacker could exploit this vulnerability by elevating their read-only permissions to those of a high-privileged user. A successful exploit could allow the attacker to access or modify configuration settings within Cisco Catalyst SD-WAN Manager as a high-privileged user.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The attack vector involves an authenticated, remote attacker exploiting a failure in the web UI to redact sensitive information within device configurations and templates, enabling unauthorized modifications and actions.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Catalyst —
Cisco —
Francisco Burzi —
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 72 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashdec28587f2b521041aa99391620cd7026ee4503f476a4400bc6bfb598f6ad3e1dae44c912415e0911bb83d1958f87690ec8fbba1e4f804a3876b09f876cede77
Related CVEs affecting Catalyst
CVE-2026-26009 9.9 Catalyst is a platform built for enterprise game server hosts, game communiti... CVE-2025-20341 8.8 A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an aut... CVE-2026-20224 8.6 A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-W... CVE-2026-20084 8.6 A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could a... CVE-2026-20086 8.6 A vulnerability in the processing of Control and Provisioning of Wireless Acc...
View all Catalyst CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →