Security Advisory Desk
mediumQCS priority 82/100Cisco

Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability

A security flaw in the Cisco Catalyst SD-WAN Manager's web interface lets someone with basic login access see sensitive information in plain text, like passwords, by viewing certain logs. This problem happens because the system doesn’t properly restrict access to some types of templates that should be encrypted. Attackers could use these leaked details to take over parts of the network. Cisco has released software updates that fix this issue, but there are no temporary workarounds.

Published 7/8/2026, 9:26:16 pmVerified 7/8/2026, 10:00:27 pmRevision 2
Cisco medium network security advisory visual

In plain language

What this advisory means

A security flaw in the Cisco Catalyst SD-WAN Manager's web interface lets someone with basic login access see sensitive information in plain text, like passwords, by viewing certain logs. This problem happens because the system doesn’t properly restrict access to some types of templates that should be encrypted. Attackers could use these leaked details to take over parts of the network. Cisco has released software updates that fix this issue, but there are no temporary workarounds.

Technical explanation

How the issue affects the environment

The vulnerability exists in Cisco Catalyst SD-WAN Manager’s web-based management interface and involves insufficient enforcement of access controls for specific template types. These templates are excluded from the encryption allowlist, allowing an authenticated, remote attacker with low privileges to access sensitive information by viewing logs stored locally or on remote logging servers. This clear-text exposure of authentication credentials can lead to further compromise of network infrastructure and connected services. The issue carries a Medium severity rating (CVSS score 6.5) and is tracked as CVE-2026-20294. Cisco has released fixed software versions to remediate the vulnerability.

Operational impact

Why teams should care

If exploited, this vulnerability could expose sensitive authentication credentials to attackers with limited access, potentially enabling unauthorized access to critical network infrastructure and services. Such exposure risks further compromise of network security, potentially leading to downtime, data breaches, or service disruptions. Organizations relying on affected Cisco SD-WAN management software must apply updates promptly to prevent exploitation.

Immediate action

Cisco strongly recommends upgrading Cisco Catalyst SD-WAN Manager to the fixed software releases listed in the advisory to fully remediate the vulnerability. Customers using Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.602 or later require no additional action. Those needing support should contact Cisco Technical Assistance Center (TAC).

Affected and fixed releases

Affected versionsAll versions prior to fixed releases noted below
Fixed versions20.9.10, 20.12.8, 20.15.6, 20.18.4, 26.1.2, 26.2.1, Cloud-based Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.602

Temporary risk reduction

There are no workarounds that mitigate this vulnerability. Only upgrading to a fixed software release fully addresses the issue.

Evidence and validation checklist

  • Cisco Security Advisory on Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability (cisco-sa-sdwan-infodis-SPuJBDCe)
  • Vulnerability details including CWE-319 and CVE-2026-20294
  • Cisco fixed release version information
  • Statement that no workarounds exist
  • Acknowledgment of reporting by CISA

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
Cisco Catalyst SD-WAN Manager Information | Advisory | QCS