CVE-2026-20133

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file

Severity
Medium 6.5
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Yes — in CISA KEV
Added Apr 20, 2026
EPSS
0.318
98.3th percentile
Discovered by
Vendor
Vendor-published field
Published
Feb 25, 2026
Assigned by cisco

Description

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.

Weakness: CWE-200

Affected products

Vendor Product Category Matched by
Cisco Cisco Catalyst SD-WAN Manager Network & Security Management cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco Catalyst SD-WAN Manager

Vendor advisory

cisco-sa-sdwan-authbp-qwCX8D4v

Cisco Catalyst SD-WAN Vulnerabilities

Cisco’s rating: Critical (advisory CVSS 9.8) · Published Feb 25, 2026 · updated Apr 22, 2026 (revision 1.3)

Bug IDs: CSCws33583 , CSCws33584 , CSCws33585 , CSCws33586 , CSCws33587 , CSCws93470

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?