PatchSiren cyber security CVE debrief
CVE-2026-20209 Cisco CVE debrief
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user. This vulnerability exists because sensitive session information is recorded in audit logs. An attacker could exploit this vulnerability by elevating their read-only permissions in Cisco Catalyst SD-WAN Manager to those of a high-privileged user. A successful exploit could allow the attacker to perform actions as a high-privileged user.
- Vendor
- Cisco
- Product
- Cisco Catalyst SD-WAN Manager
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-06-29
Who should care
Security teams and administrators responsible for Cisco Catalyst SD-WAN Manager should be aware of this vulnerability and take steps to mitigate it. This vulnerability could allow an attacker to gain elevated privileges and perform actions as a high-privileged user, potentially leading to unauthorized access and control.
Technical summary
The vulnerability is caused by sensitive session information being recorded in audit logs. An attacker could exploit this vulnerability by elevating their read-only permissions in Cisco Catalyst SD-WAN Manager to those of a high-privileged user. The vulnerability has a CVSS score of 5.4 and a medium severity rating. The affected product is Cisco Catalyst SD-WAN Manager, formerly known as SD-WAN vManage.
Defensive priority
This vulnerability should be prioritized for remediation due to its medium severity rating and potential impact on the security of Cisco Catalyst SD-WAN Manager. Administrators should review the affected versions and upgrade to a fixed version as soon as possible.
Recommended defensive actions
- Review the affected versions of Cisco Catalyst SD-WAN Manager and upgrade to a fixed version.
- Implement additional security measures to monitor and restrict access to the web UI.
- Review audit logs for any suspicious activity.
- Consider implementing compensating controls to limit the impact of a potential exploit.
- Monitor for any updates or patches from Cisco.
Evidence notes
The vulnerability is documented in the Cisco Security Advisory and the NVD database. The affected versions of Cisco Catalyst SD-WAN Manager are listed in the CPE criteria. The vulnerability has a CVSS score of 5.4 and a medium severity rating.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-20209 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-20209
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-20209 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20209
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk
[email protected] - Not Applicable
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.