CVE-2026-20128 is a high-severity vulnerability (CVSS 7.5) in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager, affecting versions prior to 20.18. An authenticated, local attacker with vmanage credentials can exploit a credential file containing the DCA password to gain DCA user privileges on an affected system. This requires high privileges (PR:H) and high attack complexity (AC:H) but can lead to full compromise of confidentiality, integrity, and availability (C:H, I:H, A:H). While there is no public exploit code (Metasploit, Nuclei, ExploitDB) or KEV entry, the vulnerability has garnered significant community discussion (6 mentions) and media coverage (3 articles), with some reports indicating ongoing exploitation of similar Cisco SD-WAN flaws.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.9.8.2CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* | ||
>= 20.10, < 20.12.5.3CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* | ||
>= 20.13, < 20.15.4.2CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* | ||
>= 20.16, < 20.18CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* | ||
20.12.6CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:20.12.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco Catalyst SD-WAN Vulnerabilities
Mar 18, 2026Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20128)
Mar 18, 2026Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20128)
Mar 18, 2026Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20128)
Mar 18, 2026Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20128)
Mar 18, 2026Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20128)
Mar 18, 2026Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20128)
Mar 18, 2026Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20128)
Mar 18, 2026Cisco Catalyst SD-WAN Vulnerabilities
Feb 25, 2026