CVE-2026-20128: Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file…
How it works
The underlying weakness is CWE-257. The product writes credentials for the DCA user to a file that remains readable by lower-privileged local accounts. An attacker who already holds a local session can simply open or copy that file to retrieve the stored credentials and assume the higher-privileged DCA identity.
Am I affected? How to find it in your systems
Inventory all deployments of Cisco Catalyst SD-WAN Manager in your environment. Confirm the installed version and configuration against the vendor advisory, because only specific builds contain the affected credential file. Review local filesystem permissions and service accounts that run the manager components. Examine authentication and file-access logs for unexpected reads of credential paths by non-DCA users.
How to remediate
Apply the vendor update referenced in the official advisory. After patching, follow CISA’s Emergency Directive 26-03 and the Hunt & Hardening Guidance for Cisco SD-WAN Devices. Review and tighten local filesystem permissions around credential storage locations. Ensure that only the intended DCA service account can read the file.
If you can't patch immediately
Isolate SD-WAN Manager instances on a dedicated management network segment that restricts inbound access to trusted administrative hosts. Monitor for anomalous local file reads and privilege-escalation attempts. Apply applicable BOD 22-01 controls for any cloud-hosted instances. If compensating measures cannot be implemented, discontinue use of the affected product until remediation is complete.
If your data may have been exposed
Compromises that begin with local credential access can lead to further network intrusion. Run a free exposure scan of your organization’s email addresses against known breach data to determine whether any accounts have already appeared in public listings.
AICompiled with AI assistance from public sources and published under our editorial standards.