CVE-2026-20294: Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20294?
The severity of CVE-2026-20294 is medium with a CVSS score of 6.5.
What does CVE-2026-20294 affect?
CVE-2026-20294 affects the web-based management interface of Cisco Catalyst SD-WAN Manager.
How does CVE-2026-20294 allow information disclosure?
CVE-2026-20294 allows an authenticated, remote attacker to view sensitive information in clear text due to insufficient access control enforcement.
How can I mitigate CVE-2026-20294?
To mitigate CVE-2026-20294, ensure that proper access controls are implemented and regularly review user permissions.
Is there a patch available for CVE-2026-20294?
As of now, specific details regarding a patch for CVE-2026-20294 have not been provided.