Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-59.
Published: 2026-08-05
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper link resolution before file access flaw classified as CWE‑59. During file reads the system does not correctly verify that a file or directory is not a symbolic link that points to another location, which allows an attacker to read arbitrary files whose names are supplied through the link resolution process. The impact is the ability to read sensitive configuration or credential files and thereby compromise confidentiality of the SD‑WAN deployment.

Affected Systems

The flaw affects Cisco Catalyst SD‑WAN Controller and Cisco Catalyst SD‑WAN Manager products. No specific version information was provided in the advisory, so all current and older releases are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 9.1 reflects a high severity with a high impact. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. While the specific attack vector is not detailed, the context of SD‑WAN management suggests that remote exploitation through the control plane or management interfaces is plausible, especially if an attacker can supply a crafted link name. The high score indicates that the flaw is exploitable with moderate complexity and that successful exploitation would compromise confidential information. Therefore, the risk to an organization deploying these products is significant until a vendor‑issued fix is implemented.

Generated by OpenCVE AI on August 5, 2026 at 18:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Cisco SD‑WAN software hardening release that addresses the link resolution flaw.
  • Restrict access to the SD‑WAN controller and manager management interfaces to trusted networks or administrators only.
  • Validate paths on any custom code that performs file access to ensure symbolic links are resolved securely and deny access to unauthorized files.

Generated by OpenCVE AI on August 5, 2026 at 18:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 21:30:00 +0000


Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco catalyst Sd-wan Manager
Cisco cisco Catalyst Sd-wan Controller
Vendors & Products Cisco
Cisco catalyst Sd-wan Manager
Cisco cisco Catalyst Sd-wan Controller

Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-59.
Title Cisco SD-WAN Software Security Hardening Release - Improper Link Resolution Before File Access
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Catalyst Sd-wan Manager Cisco Catalyst Sd-wan Controller
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-14T21:00:51.145Z

Reserved: 2025-10-08T11:59:15.409Z

Link: CVE-2026-20310

cve-icon Vulnrichment

Updated: 2026-08-14T21:00:51.145Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-05T17:16:51.520

Modified: 2026-08-14T21:17:16.643

Link: CVE-2026-20310

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:49Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')