CVE-2026-20182
CRITICAL KEV NUCLEICisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Title source: cnaExploitation Summary
CVE-2026-20182 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 14, 2026.
EIP tracks 5 public exploits from researchers including Nxploited, HORKimhab, portbuster1337, including a Metasploit module auxiliary/admin/networking/cisco_sdwan_vhub_auth_bypass.
A Nuclei detection template is also available.
AI-analyzed exploit summary The repository contains a functional Python exploit for CVE-2026-20182, targeting Cisco Catalyst SD-WAN Controller's peering authentication bypass. The script implements a DTLS-based attack to bypass authentication and gain high-privileged internal access.
Description
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks. A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
Exploits (5)
The repository contains a functional Python exploit for CVE-2026-20182, targeting Cisco Catalyst SD-WAN Controller's peering authentication bypass. The script implements a DTLS-based attack to bypass authentication and gain high-privileged internal access.
The repository contains no actual exploit code or technical details for CVE-2026-20182. It only includes a generic README with legal disclaimers, a LICENSE file, and a template file for CVE IDs.
This repository contains a functional exploit for CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller/Manager. The exploit leverages a flaw in the vdaemon service (UDP/12346) to bypass authentication by impersonating a vHub device and injects an SSH public key for persistent access.
The repository claims to provide an exploit for CVE-2026-20182, an authentication bypass in Cisco Catalyst SD-WAN Controller/Manager, but lacks actual exploit code. Instead, it directs users to an external download link (tinyurl.com), which is a common tactic for malicious or monetized exploits.
This Metasploit module exploits an authentication bypass vulnerability (CVE-2026-20182) in Cisco Catalyst SD-WAN Controller by leveraging a missing verification path for vHub device types in the DTLS handshake process, allowing SSH key injection for persistent access.
Nuclei Templates (1)
port:12346 product:"Cisco SD-WAN"
port="12346" && product="Cisco SD-WAN"
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H