CVE-2026-20128: Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
Other sources
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Catalyst SD-WAN Managerto a version that resolves this vulnerability.Fixed in 20.18 - Compensating control
Adhere to the applicable BOD 22-01 guidance for cloud services, or discontinue use of Cisco Catalyst SD-WAN Manager if mitigations are not available.
- Compensating control
Assess exposure and mitigate risks by following CISA Emergency Directive 26-03 and CISA’s 'Hunt & Hardening Guidance for Cisco SD-WAN Devices'.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20128?
CVE-2026-20128 has a severity rating that may vary based on the context of the attack but is classified as a medium-level vulnerability.
How can I fix CVE-2026-20128?
To fix CVE-2026-20128, ensure that you update your Cisco Catalyst SD-WAN Manager to a version later than 20.18.
Who is affected by CVE-2026-20128?
CVE-2026-20128 affects systems using Cisco Catalyst SD-WAN Manager version 20.18 and earlier.
What are the potential impacts of CVE-2026-20128?
The potential impacts of CVE-2026-20128 include unauthorized access and privilege escalation for authenticated, local attackers.
Is there a workaround for CVE-2026-20128?
There are currently no known workarounds for CVE-2026-20128, so updating to a fixed version is recommended.