


Perceptive Security
SOC/SIEM Consultancy

Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user p…
Published:
20 april 2026 om 00:00:00
Alert date:
21 april 2026 om 07:08:02
Source:
cisa.gov
Network Infrastructure, Identity & Access
Cisco Catalyst SD-WAN Manager contains a vulnerability that stores passwords in a recoverable format on the filesystem. This allows authenticated local attackers with low privileges to access credential files and escalate privileges to DCA user level. The vulnerability affects Cisco SD-WAN systems and has prompted CISA to issue emergency directives and mitigation guidance. Organizations are advised to follow CISA's hunt and hardening guidance to secure their SD-WAN infrastructure.
Technical details
Mitigation steps:
Affected products:
Cisco Catalyst SD-WAN Manager
Related links:
https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems
https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v
https://nvd.nist.gov/vuln/detail/CVE-2026-20128
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
