AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-20294

MEDIUM · CVSS 6.5 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability in Cisco Catalyst SD-WAN Manager's web-based management interface allows authenticated, low-privileged attackers to access sensitive information in clear text due to inadequate access control for certain template types. This could lead to the exposure of authentication credentials, potentially compromising network infrastructure and connected services. Organizations using Cisco SD-WAN Manager should prioritize remediation to mitigate the risk of unauthorized data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-20294
Severity
MEDIUM
CVSS
6.5
EPSS
0.13%
Cisco

Original NVD Description

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services.