Record summary

CVE-2026-20126 has a selected CVSS score of 8.8 (high).

Description

A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerability is due to an insufficient user authentication mechanism in the REST API. An attacker could exploit this vulnerability by sending a request to the REST API of the affected system. A successful exploit could allow the attacker to gain root privileges on the underlying operating system.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List20.1.12affected
19.2.1affected
18.4.4affected
18.4.5affected
20.1.1.1affected
20.1.1affected
19.3.0affected
19.2.2affected
19.2.099affected
18.3.6affected
18.3.7affected
19.2.0affected
Showing 12 of 335 version ranges

References

2