Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information issues that are grouped under the Common Weakness Enumeration (CWE) CWE-312.
Published: 2026-08-05
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from the Cisco Catalyst SD‑WAN Controller and Manager storing sensitive credentials—such as passwords, tokens, or API keys—in cleartext. This design flaw, categorized as CWE‑312, permits an attacker who can read the configuration or file system data to obtain those credentials. The resulting loss of confidentiality could allow an attacker to gain full control over the SD‑WAN fabric or use the stolen information to move laterally within the organization’s network.

Affected Systems

All versions of Cisco Catalyst SD‑WAN Controller and Cisco Catalyst SD‑WAN Manager are affected. The advisory does not specify exact version ranges, but any deployment using the default configuration that preserves credentials in plaintext is vulnerable.

Risk and Exploitability

The CVSS score of 8.8 classifies the issue as high severity, emphasizing the serious confidentiality risk. EPSS data is not available, so the current likelihood of exploitation is unknown, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the most likely attack vector is an attacker with privileged access to the controller or manager’s configuration files, or access to the file system where the cleartext credentials reside.

Generated by OpenCVE AI on August 5, 2026 at 18:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Cisco SD‑WAN security hardening release that removes cleartext credential storage.
  • Reconfigure remaining credentials to use encrypted or tokenized storage and verify that no passwords are written to disk.
  • Restrict administrative access to the SD‑WAN Controller and Manager to trusted personnel and enforce least‑privilege principles.
  • Monitor system logs for unexpected read attempts of configuration files and investigate any anomalies promptly.

Generated by OpenCVE AI on August 5, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 21:30:00 +0000


Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco catalyst Sd-wan Manager
Cisco cisco Catalyst Sd-wan Controller
Vendors & Products Cisco
Cisco catalyst Sd-wan Manager
Cisco cisco Catalyst Sd-wan Controller

Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information issues that are grouped under the Common Weakness Enumeration (CWE) CWE-312.
Title Cisco Catalyst SD-WAN Security Hardening Release - Information Disclosure Vulnerabilities
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cisco Catalyst Sd-wan Manager Cisco Catalyst Sd-wan Controller
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-14T21:00:51.007Z

Reserved: 2025-10-08T11:59:15.409Z

Link: CVE-2026-20312

cve-icon Vulnrichment

Updated: 2026-08-14T21:00:51.007Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-05T17:16:52.093

Modified: 2026-08-14T21:17:17.040

Link: CVE-2026-20312

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:47Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information