Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-20304: Cisco Catalyst SD-WAN Access Control Flaw Exposes Network
CVE-2026-20304
CVE-2026-20304
Summary
Cisco Catalyst SD-WAN software has an access control issue that could allow unauthorized users to access sensitive parts of the network. This is a security concern because it could lead to unauthorized changes or data theft. To fix this issue, Cisco has released a software update that addresses the problem.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| cisco | cisco catalyst sd-wan controller | 20.6.4 |
| cisco | cisco catalyst sd-wan manager | 20.1.12 |
Original title
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resul...
Original description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
mitre CVSS3.1
9.9
Vulnerability type
CWE-284
Improper Access Control
Published: 5 Aug 2026 · Updated: 5 Aug 2026 · First seen: 5 Aug 2026