CVE-2026-20152

MEDIUM

Cisco Secure Web Appliance Authentication Service Traffic Bypass Vulnerability

Title source: cna
STIX 2.1

Description

A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass authentication policy requirements. This vulnerability is due to improper validation of user-supplied authentication input in HTTP requests. An attacker could exploit this vulnerability by sending HTTP requests that contain specific authentication requests to an affected device. A successful exploit could allow the attacker to bypass policy enforcement on the device. There is no direct impact to the Cisco Secure Web Appliance. However, as a result of exploiting this vulnerability, an attacker could send HTTP requests that should be restricted through the device.

Scores

CVSS v3 5.3
EPSS 0.0008
EPSS Percentile 24.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-305
Status published
Products (50)
Cisco/Cisco Secure Web Appliance 11.8.0-414
Cisco/Cisco Secure Web Appliance 11.8.0-429
Cisco/Cisco Secure Web Appliance 11.8.0-453
Cisco/Cisco Secure Web Appliance 11.8.1-023
Cisco/Cisco Secure Web Appliance 11.8.3-018
Cisco/Cisco Secure Web Appliance 11.8.3-021
Cisco/Cisco Secure Web Appliance 11.8.4-004
Cisco/Cisco Secure Web Appliance 12.0.1-268
Cisco/Cisco Secure Web Appliance 12.0.1-334
Cisco/Cisco Secure Web Appliance 12.0.2-004
... and 40 more
Published Apr 15, 2026
Tracked Since Apr 15, 2026