CVE-2026-20127: Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated…
How it works
The weakness is categorized as CWE-287, improper authentication. The peering authentication mechanism in the affected systems does not enforce checks correctly.
- An attacker sends crafted requests to the Controller or Manager.
- The requests allow login as an internal high-privileged non-root account.
- From that account the attacker can reach NETCONF and alter fabric configuration.
Exploit details beyond the summary must be confirmed against the vendor advisory.
Am I affected? How to find it in your systems
Cisco Catalyst SD-WAN Controller (formerly vSmart) and Manager (formerly vManage) run in enterprise SD-WAN deployments that centralize control-plane functions. Inventory all instances of these components in your environment, including any cloud-hosted deployments.
- Compare installed versions and configurations against the vendor advisory to determine exposure.
- Review NETCONF session logs and administrative login records for unexpected internal high-privileged accounts or configuration changes originating from external sources.
- Follow CISA Emergency Directive 26-03 and the associated Hunt & Hardening Guidance for Cisco SD-WAN Devices to locate affected systems.
How to remediate
Apply the vendor update referenced in the advisory as the primary fix. After patching, review and enforce strict access controls on management interfaces and NETCONF.
- Disable unnecessary peering or external management exposure where operationally feasible.
- Ensure authentication mechanisms are functioning as intended by testing against current vendor guidance.
If you can't patch immediately
Adhere to CISA Emergency Directive 26-03 and the Hunt & Hardening Guidance for Cisco SD-WAN Devices. Apply network segmentation to limit reachability of Controller and Manager instances from untrusted networks.
- Monitor for anomalous NETCONF activity and administrative logins.
- Consider virtual patching or request filtering at network boundaries if supported by existing controls.
- For cloud services, follow BOD 22-01 requirements; discontinue use of the product if no mitigations can be applied.
If your data may have been exposed
Actively exploited authentication bypass vulnerabilities have led to unauthorized access and subsequent breaches. Organizations can run a free exposure scan of their email addresses to check against known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.