CVE-2026-20133: Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.
Other sources
Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
- Compensating control
Adhere to CISA Emergency Directive 26-03 and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices” to assess exposure and mitigate risks associated with Cisco SD‑WAN devices.
- Compensating control
Restrict access to the vshell and limit/remove netadmin privileges to only authorized personnel; audit and tighten vshell access controls to prevent unauthorized viewing of sensitive information.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20133?
CVE-2026-20133 is considered to have a high severity due to the potential for unauthorized information disclosure.
How do I fix CVE-2026-20133?
To fix CVE-2026-20133, ensure that you apply the latest security patch provided by Cisco for the Catalyst SD-WAN Manager.
What systems are affected by CVE-2026-20133?
CVE-2026-20133 affects Cisco Catalyst SD-WAN Manager versions that have insufficient file system access restrictions.
What type of vulnerability is CVE-2026-20133?
CVE-2026-20133 is an information disclosure vulnerability that allows unauthorized access to sensitive information.
Can CVE-2026-20133 be exploited remotely?
Yes, CVE-2026-20133 can be exploited remotely by an unauthenticated attacker.