PT-2026-21955 · Cisco · Cisco Catalyst Sd-Wan Manager

Arthur Vidineyev

·

Published

2026-02-25

·

Updated

2026-03-05

·

CVE-2026-20128

CVSS v3.1
7.5
VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Catalyst SD-WAN Manager versions prior to 20.18
Description A security issue exists within the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager. A local attacker with valid
vmanage
credentials can potentially gain DCA user privileges on a vulnerable system. This is due to the presence of a credential file containing the DCA user's password on the affected system. An attacker could access the filesystem with low-privileged access and read this file, potentially gaining access to other affected systems and elevated privileges.
Recommendations Upgrade to Cisco Catalyst SD-WAN Manager version 20.18 or later.

Fix

Weakness Enumeration

Related Identifiers

BDU:2026-02320
CVE-2026-20128

Affected Products

Cisco Catalyst Sd-Wan Manager