peter bassill · operator
$ cve CVE-2026-20128 JSON

CVE-2026-20128 KEV

7.5
HIGH · CVSS 3.1 · EPSS 7.1% (pctl 94)

Patch first

On CISA KEV — known exploited in the wild, due 2026-04-23.

Description

A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS7.06% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-257
On CISA KEVyes — remediate by 2026-04-23
Public exploitnone known
Published2026-02-25
Last modified2026-06-17

CISA KEV

NameCisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
Added2026-04-20
Due2026-04-23
Vendor / productCisco / Catalyst SD-WAN Manager
Ransomware usenone reported

Affected (1)

VendorProduct
ciscocatalyst sd-wan manager

References

→ the Explorer  ·  watch your stack  ·  NVD