Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Critical

Cisco Catalyst SD-WAN Manager API Authentication Bypass

IdentifiersCVE-2026-20129CWE-287· Improper Authentication

CVE-2026-20129 is a critical improper authentication vulnerability in the API user authentication component of Cisco Catalyst SD-WAN Manager. The flaw is caused by improper authentication of requests sent to the API, allowing authentication controls to be bypassed. An unauthenticated remote attacker can exploit the issue by sending a crafted request to the API of an affected system. Successful exploitation allows the attacker to gain access to the system as a user with the netadmin role and execute commands with netadmin privileges. Cisco states that releases 20.18 and later are not affected.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated remote attacker to bypass authentication and obtain access equivalent to a netadmin user on the affected Cisco Catalyst SD-WAN Manager instance. This enables command execution with netadmin privileges and results in high impact to confidentiality, integrity, and availability, consistent with the reported CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, restrict access to Cisco Catalyst SD-WAN Manager management interfaces and API endpoints from untrusted or unsecured networks, remove direct internet exposure, place the system behind a firewall, and limit access to dedicated management networks. Disable unnecessary services such as HTTP and FTP where applicable, enforce secure management communications, monitor logs for anomalous API activity or unauthorized access, and review the system for unexpected account additions or configuration changes. Cisco hardening guidance and advisory-specific recommendations should be followed until upgrades are completed.

Remediation

Patch, then assume compromise.

Upgrade Cisco Catalyst SD-WAN Manager to a fixed release. Cisco states that releases 20.18 and later are not affected. Supporting content also references fixed versions across supported trains, including 20.9.8.2 for 20.9, 20.12.5.3 or 20.12.6.1 for 20.12, 20.15.4.2 for 20.13 through 20.15, and 20.18.2.1 for 20.16 and 20.18, with versions earlier than 20.9.1 requiring migration to a fixed release. Follow Cisco’s official upgrade matrix and advisory guidance for the deployed train.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Cisco SystemsCatalyst SD-WAN Managerapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity8

Community discussion across Reddit, Mastodon, and other social sources.