CVE-2026-20129: Cisco Catayst SD-WAN Authentication Bypass Vulnerability
A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. The vulnerability is due to improper authentication for requests that are sent to the API. An attacker could exploit this vulnerability by sending a crafted request to the API of an affected system. A successful exploit could allow the attacker to execute commands with the privileges of the netadmin role. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20129?
CVE-2026-20129 has been classified as high severity due to its potential to allow unauthorized access to critical system functions.
How do I fix CVE-2026-20129?
To fix CVE-2026-20129, users should update their Cisco Catalyst SD-WAN Manager to a version beyond 20.18 that addresses this vulnerability.
What are the potential impacts of CVE-2026-20129?
The potential impacts of CVE-2026-20129 include unauthorized access to sensitive system configurations and the ability to perform actions as a user with the netadmin role.
Who is affected by CVE-2026-20129?
CVE-2026-20129 affects installations of Cisco Catalyst SD-WAN Manager up to version 20.18.
Is there a workaround for CVE-2026-20129?
Currently, there are no known workarounds for CVE-2026-20129, and users are advised to apply the available fixes as soon as possible.