CVE-2026-20133 describes a sensitive information disclosure vulnerability in Cisco Catalyst SD-WAN Manager, stemming from insufficient file system access restrictions. An unauthenticated, remote attacker can exploit this by accessing the system's API to read sensitive data from the underlying operating system. Rated 7.5 HIGH on CVSS, this vulnerability has a low attack complexity and requires no user interaction, but only impacts confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.9.8.2CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* | ||
>= 20.10, < 20.12.5.3CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* | ||
>= 20.13, < 20.15.4.2CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* | ||
>= 20.16, < 20.18.2.1CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* | ||
20.12.6CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:20.12.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco Catalyst SD-WAN Vulnerabilities
Mar 18, 2026Cisco Catalyst SD-WAN Manager Information Disclosure (CVE-2026-20133)
Mar 17, 2026Cisco Catalyst SD-WAN Manager Information Disclosure (CVE-2026-20133)
Mar 17, 2026Cisco Catalyst SD-WAN Manager Information Disclosure (CVE-2026-20133)
Mar 17, 2026Cisco Catalyst SD-WAN Manager Information Disclosure (CVE-2026-20133)
Mar 17, 2026Cisco Catalyst SD-WAN Manager Information Disclosure (CVE-2026-20133)
Mar 17, 2026Cisco Catalyst SD-WAN Manager Information Disclosure (CVE-2026-20133)
Mar 17, 2026Cisco Catalyst SD-WAN Vulnerabilities
Feb 25, 2026