Description
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.

This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services.
Published: 2026-08-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the web‑based management interface of Cisco Catalyst SD‑WAN Manager allows an authenticated, remote attacker to view sensitive information in clear text. The root cause is insufficient access control enforcement for specific template types that are not present in the encryption allowlist. By exploiting this weakness the attacker can read logs on the local device or on a remote logging server and expose authentication credentials, which could then be used to compromise additional network resources.

Affected Systems

Cisco Catalyst SD‑WAN Manager is the only product explicitly listed as affected by this vulnerability.

Risk and Exploitability

The CVSS score of 6.5 categorizes the issue as moderate severity. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog, indicating a lower public exploitation probability. However, successful exploitation requires an authenticated account with low privileges; once credentials or logs are obtained, an attacker has the potential to elevate privileges and extend compromise across the network. The attack vector is inferred to be remote via the web interface, as the description specifies remote interaction with the management console.

Generated by OpenCVE AI on August 5, 2026 at 18:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or upgrade to the latest version of Cisco Catalyst SD‑WAN Manager that resolves the access control flaw.
  • Restrict or remove template types that are not required and ensure that all remaining templates are included in the encryption allowlist.
  • Enforce encryption and strict access controls on all audit and operational logs so that credential data cannot be read in clear text by unauthorized users.

Generated by OpenCVE AI on August 5, 2026 at 18:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco catalyst Sd-wan Manager
Vendors & Products Cisco
Cisco catalyst Sd-wan Manager

Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services.
Title Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
Weaknesses CWE-319
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Cisco Catalyst Sd-wan Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-05T17:45:13.118Z

Reserved: 2025-10-08T11:59:15.405Z

Link: CVE-2026-20294

cve-icon Vulnrichment

Updated: 2026-08-05T17:38:58.628Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-05T17:16:49.877

Modified: 2026-08-06T15:44:56.043

Link: CVE-2026-20294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:15:07Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information