CVE-2026-20133
Description
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system.
This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.
Summary dbcve.org
This Cisco Catalyst SD-WAN vulnerability allows an authenticated attacker with netadmin privileges to access the vshell and read sensitive information from the underlying operating system due to insufficient file system restrictions. The attacker can exploit this to view files they should not have access to on the affected system.
Mitigation
Apply Cisco's official patch when available and restrict vshell access to only necessary administrative personnel. Implement principle of least privilege for file system permissions on affected systems.