CVE-2026-20304
Cisco · Catalyst SD-WAN Controller and Manager
Cisco Catalyst SD-WAN components are vulnerable to improper access control, which could allow an authenticated attacker to gain unauthorized privileges.
Executive summary
Critical access control vulnerabilities in Cisco Catalyst SD-WAN software create a high risk for privilege escalation and unauthorized administrative access.
Vulnerability
This issue stems from improper access control (CWE-284), where a user with low privileges may be able to perform unauthorized actions or access restricted system areas.
Business impact
This vulnerability carries a CVSS score of 9.9, indicating that it could result in a total compromise of the affected environment. Unauthorized access to SD-WAN management functions could allow attackers to alter network routing, intercept traffic, or gain persistent control over the infrastructure, causing severe operational and security damage.
Remediation
Immediate Action: Update all Cisco Catalyst SD-WAN Controller and Manager instances to the latest version provided by Cisco to remediate the access control flaws.
Proactive Monitoring: Monitor management interfaces for suspicious privilege escalation attempts or unauthorized configuration changes.
Compensating Controls: Restrict administrative access to the SD-WAN controller using multi-factor authentication and role-based access controls to minimize the impact of a compromised account.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations should treat this vulnerability with the utmost urgency. Schedule and perform the recommended software updates immediately to prevent potential privilege escalation and ensure the integrity of the network management plane.