VDB

CVE-2026-20209

CVE-2026-20209 PUBLISHED CVSS 5.400000095367432 MEDIUM

CVE-2026-20182 is a critical authentication bypass affecting the DTLS-based control-connection handshake in Cisco Catalyst SD-WAN Controller and SD-WAN Manager. The flaw exists because, when a connecting peer declares itself to be a vHub device, the system omits device-type-specific certificate verification yet still marks the peer as authenticated. An unauthenticated remote attacker can exploit this by sending a crafted DTLS handshake sequence that bypasses authentication checks and establishes a trusted control-plane peer relationship. Once authenticated, the attacker can issue arbitrary configuration commands across the SD-WAN fabric or establish persistent administrative access. CVE-2026-20224 is an XML External Entity (XXE) injection vulnerability in the web UI of Cisco Catalyst SD-WAN Manager. The vulnerability is caused by improper handling of XML External Entity entries during XML parsing. An unauthenticated remote attacker can send a crafted HTTP request to exploit this flaw and read arbitrary files stored on the underlying system, without requiring valid credentials. CVE-2026-20209 is a privilege escalation vulnerability in the web UI of Cisco Catalyst SD-WAN Manager. The vulnerability exists because sensitive session information is recorded in audit logs. An authenticated remote attacker with read-only permissions can retrieve privileged session tokens from those logs and use them to perform actions as a high-privileged user. CVE-2026-20210 is a privilege escalation vulnerability in the web UI of Cisco Catalyst SD-WAN Manager. The vulnerability is caused by a failure to redact sensitive information within device configurations and templates. An authenticated remote attacker with read-only permissions can access this exposed sensitive information and use it to elevate their privileges to those of a high-privileged user.

EPSS 0.03% · 10.0th percentile

Risk Scores

CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.03%
10.0th percentile

Affected Products

VendorProductVersions
CiscoCisco Catalyst SD-WAN Controller (formerly vSmart); all deployment types (On-Prem, Cloud-Pro, Cisco Managed Cloud, FedRAMP); releases prior to 20.9.9.1, 20.12.5.4 / 20.12.6.2 / 20.12.7.1, 20.15.4.4 / 20.15.5.2, 20.18.2.2, 26.1.1.1
CiscoCisco Catalyst SD-WAN Manager (formerly vManage); all deployment types; releases prior to 20.9.9.1, 20.12.5.4 / 20.12.6.2 / 20.12.7.1, 20.15.4.4 / 20.15.5.2, 20.18.2.2, 26.1.1.1

Timeline

  • May 14, 2026 CVE Published
  • May 14, 2026 PoC Published
  • May 15, 2026 CVE Updated
  • May 15, 2026 Security Advisory
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›