In plain language
What this advisory means
A security flaw in the Cisco Catalyst SD-WAN Manager's web interface lets someone with basic login access see sensitive information in plain text, like passwords, by viewing certain logs. This problem happens because the system doesn’t properly restrict access to some types of templates that should be encrypted. Attackers could use these leaked details to take over parts of the network. Cisco has released software updates that fix this issue, but there are no temporary workarounds.
Technical explanation
How the issue affects the environment
The vulnerability exists in Cisco Catalyst SD-WAN Manager’s web-based management interface and involves insufficient enforcement of access controls for specific template types. These templates are excluded from the encryption allowlist, allowing an authenticated, remote attacker with low privileges to access sensitive information by viewing logs stored locally or on remote logging servers. This clear-text exposure of authentication credentials can lead to further compromise of network infrastructure and connected services. The issue carries a Medium severity rating (CVSS score 6.5) and is tracked as CVE-2026-20294. Cisco has released fixed software versions to remediate the vulnerability.
Operational impact
Why teams should care
If exploited, this vulnerability could expose sensitive authentication credentials to attackers with limited access, potentially enabling unauthorized access to critical network infrastructure and services. Such exposure risks further compromise of network security, potentially leading to downtime, data breaches, or service disruptions. Organizations relying on affected Cisco SD-WAN management software must apply updates promptly to prevent exploitation.
Immediate action
Cisco strongly recommends upgrading Cisco Catalyst SD-WAN Manager to the fixed software releases listed in the advisory to fully remediate the vulnerability. Customers using Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.602 or later require no additional action. Those needing support should contact Cisco Technical Assistance Center (TAC).
Affected and fixed releases
Temporary risk reduction
There are no workarounds that mitigate this vulnerability. Only upgrading to a fixed software release fully addresses the issue.
Evidence and validation checklist
- Cisco Security Advisory on Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability (cisco-sa-sdwan-infodis-SPuJBDCe)
- Vulnerability details including CWE-319 and CVE-2026-20294
- Cisco fixed release version information
- Statement that no workarounds exist
- Acknowledgment of reporting by CISA
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
