Impact
The vulnerability identified as CVE-2026-20304 is an improper access control flaw (CWE-284) in Cisco Catalyst SD‑WAN Controller and Manager software. Improper access control can allow an attacker to gain unauthorized access to protected resources, potentially reading or modifying configuration data or disrupting network services. Based on the description, it is inferred that such unauthorized access could affect the confidentiality, integrity, or availability of the SD‑WAN fabric.
Affected Systems
Systems affected are the Cisco Catalyst SD‑WAN Controller and Cisco Catalyst SD‑WAN Manager. The official advisory notes that a hardening release addresses the issue, but specific affected software versions are not disclosed in the CVE data.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical severity level. EPSS is not available and the vulnerability is not listed in CISA KEV. The CVE description does not specify the attack vector or prerequisites; therefore the exact exploitation path is not detailed in the data. However, improper access control typically implies that an attacker with network visibility or access to the management interfaces could potentially exploit the flaw if the interfaces are reachable.
OpenCVE Enrichment