CVE-2026-20210
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perfor...
Affects 0 products across 3 vendors.
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager allows an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions due to a failure to redact sensitive information.
BSID: BS-2026-GLOBAL-063257-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-20210?
What is the CVSS score for CVE-2026-20210?
Is CVE-2026-20210 actively exploited?
How do I remediate CVE-2026-20210?
What systems are affected by CVE-2026-20210?
| CVE ID | CVE-2026-20210 |
|---|---|
| BSID | BS-2026-GLOBAL-063257-M BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
| Published | 2026-05-14 |
| Last Modified | 2026-06-29 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions on an affected system. This vulnerability exists because of a failure to redact sensitive information within device configurations and templates. An attacker could exploit this vulnerability by elevating their read-only permissions to those of a high-privileged user. A successful exploit could allow the attacker to access or modify configuration settings within Cisco Catalyst SD-WAN Manager as a high-privileged user.
Source: NIST NVD / MITRE CVE Database
The attack vector involves an authenticated, remote attacker exploiting a failure in the web UI to redact sensitive information within device configurations and templates, enabling unauthorized modifications and actions.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Catalyst | — | — |
| Cisco | — | — |
| Francisco Burzi | — | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | dec28587f2b521041aa99391620cd7026ee4503f476a4400bc6bfb598f6ad3e1dae44c912415e0911bb83d1958f87690ec8fbba1e4f804a3876b09f876cede77 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →