CVE Explorer
CVE-2026-20133
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system.
This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.
Known exploited
CISA KEV
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"Cisco Catalyst SD-WAN Manager","vendor":"Cisco","versions":[{"status":"affected","version":"17.2.6"},{"status":"affected","version":"17.2.7"},{"status":"affected","version":"17.2.8"},{"status":"affected","version":"17.2.9"},{"status":"affected","version":"17.2.10"},{"status":"affected","version":"17.2.4"},{"status":"affected","version":"17.2.5"},{"status":"affected","version":"18.3.1.1"},{"status":"affected","version":"18.3.3.1"},{"status":"affected","version":"18.3.3"},{"status":"affected","version":"18.3.4"},{"status":"affected","version":"18.3.5"},{"status":"affected","version":…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3190feac4e44664deae79310a3bae134c3f2edf06e430e686acc7452b3d8e1cb · sha256:0502ae1a2fe5192d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3190feac4e44664deae79310a3bae134c3f2edf06e430e686acc7452b3d8e1cb · sha256:0502ae1a2fe5192d… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-200","description":"Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"cwe"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3190feac4e44664deae79310a3bae134c3f2edf06e430e686acc7452b3d8e1cb · sha256:0502ae1a2fe5192d… · /containers/cna/problemTypes/0/descriptions/0
Known exploitation assertions
2 source assertions{"cwes":["CWE-200"],"dateAdded":"2026-04-20","dueDate":"2026-04-23","knownRansomwareCampaignUse":"Unknown","notes":"CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v ; https://nvd.nist.gov/vuln/detail/CVE-2026-20133","product":"Catalyst SD-WAN Manager","requiredAction":"Please adher…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:f1eccd52970a4ac9b156dc763b3e914eff6afc75469ae2f2f829c38f4761f98c · sha256:635dff916c4092c0… · /vulnerabilities/84Open source location →
{"cwes":["CWE-200"],"dateAdded":"2026-04-20","dueDate":"2026-04-23","knownRansomwareCampaignUse":"Unknown","notes":"CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v ; https://nvd.nist.gov/vuln/detail/CVE-2026-20133","product":"Catalyst SD-WAN Manager","requiredAction":"Please adher…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:bb00ecda62607d13877e4b0b81981ee90d66c9360d8cdb3f21f7cad6dbc7e4aa · sha256:16acee8334e59e44… · /vulnerabilities/81Open source location →
Source references
2 source assertions{"name":"cisco-sa-sdwan-authbp-qwCX8D4v","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3190feac4e44664deae79310a3bae134c3f2edf06e430e686acc7452b3d8e1cb · sha256:0502ae1a2fe5192d… · /containers/cna/references/0
{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20133"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3190feac4e44664deae79310a3bae134c3f2edf06e430e686acc7452b3d8e1cb · sha256:0502ae1a2fe5192d… · /containers/adp/0/references/0
Attribution and limitations
- CISA Known Exploited Vulnerabilities JSON: CISA named for provenance; do not use CISA/DHS marks or imply endorsement Source →
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.