CVE-2026-20128
Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
Description
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
Weakness: CWE-257
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Catalyst SD-WAN Manager | Network & Security Management | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco Catalyst SD-WAN Manager
Vendor advisory
cisco-sa-sdwan-authbp-qwCX8D4v
Cisco Catalyst SD-WAN Vulnerabilities
Cisco’s rating: Critical (advisory CVSS 9.8) · Published Feb 25, 2026 · updated Apr 22, 2026 (revision 1.3)
Bug IDs: CSCws33583 , CSCws33584 , CSCws33585 , CSCws33586 , CSCws33587 , CSCws93470
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from