Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
Published: 2026-08-05
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability identified as CVE-2026-20304 is an improper access control flaw (CWE-284) in Cisco Catalyst SD‑WAN Controller and Manager software. Improper access control can allow an attacker to gain unauthorized access to protected resources, potentially reading or modifying configuration data or disrupting network services. Based on the description, it is inferred that such unauthorized access could affect the confidentiality, integrity, or availability of the SD‑WAN fabric.

Affected Systems

Systems affected are the Cisco Catalyst SD‑WAN Controller and Cisco Catalyst SD‑WAN Manager. The official advisory notes that a hardening release addresses the issue, but specific affected software versions are not disclosed in the CVE data.

Risk and Exploitability

The CVSS score of 9.9 indicates a critical severity level. EPSS is not available and the vulnerability is not listed in CISA KEV. The CVE description does not specify the attack vector or prerequisites; therefore the exact exploitation path is not detailed in the data. However, improper access control typically implies that an attacker with network visibility or access to the management interfaces could potentially exploit the flaw if the interfaces are reachable.

Generated by OpenCVE AI on August 5, 2026 at 19:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Cisco Catalyst SD‑WAN controller and manager hardening release that resolves the access control flaw.
  • Restrict external network access to the controller and manager management interfaces using firewall rules or ACLs, limiting traffic to trusted sources.
  • Enable multi‑factor authentication and enforce role‑based access controls on all management interfaces to reduce privilege escalation opportunities.
  • Review and monitor security logs for anomalous authentication activity and investigate any suspicious events.

Generated by OpenCVE AI on August 5, 2026 at 19:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 21:30:00 +0000


Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco catalyst Sd-wan Manager
Cisco cisco Catalyst Sd-wan Controller
Vendors & Products Cisco
Cisco catalyst Sd-wan Manager
Cisco cisco Catalyst Sd-wan Controller

Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
Title Cisco Catalyst SD-WAN Security Hardening Release - Access Control Vulnerabilities
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Catalyst Sd-wan Manager Cisco Catalyst Sd-wan Controller
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-14T21:00:51.293Z

Reserved: 2025-10-08T11:59:15.408Z

Link: CVE-2026-20304

cve-icon Vulnrichment

Updated: 2026-08-14T21:00:51.293Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-05T17:16:50.890

Modified: 2026-08-14T21:17:16.183

Link: CVE-2026-20304

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:55Z

Weaknesses