HIGH

CVE-2026-20133

Cisco Catalyst Sd Wan Manager 2026-02-25 CVSS v3.1
CVSS
7.5
KEV

Description

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system.

This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.

Summary dbcve.org

This Cisco Catalyst SD-WAN vulnerability allows an authenticated attacker with netadmin privileges to access the vshell and read sensitive information from the underlying operating system due to insufficient file system restrictions. The attacker can exploit this to view files they should not have access to on the affected system.

Mitigation

Apply Cisco's official patch when available and restrict vshell access to only necessary administrative personnel. Implement principle of least privilege for file system permissions on affected systems.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

31.35%
Probability of exploitation in next 30 days
98.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE