RaqibCTI
CVE

CVE-2026-20128

P2
Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
Cisco · Catalyst SD-WAN Manager
Date added (CISA)
2026-04-20
Remediation due
2026-04-23
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.

Source: NVD ↗ · CISA KEV Catalog ↗