Full Report
AL26-004 - Critical vulnerability affecting Cisco Catalyst SD-WAN - CVE-2026-20127
Analysis Summary
# Vulnerability: Cisco Catalyst SD-WAN Critical Authentication Bypass
## CVE Details
- **CVE ID:** CVE-2026-20127
- **CVSS Score:** 10.0 (Critical) - *Based on description of unauthenticated remote admin access*
- **CWE:** CWE-287 (Improper Authentication)
## Affected Systems
- **Products:**
- Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart)
- Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage)
- **Versions:**
- Earlier than 20.9
- 20.9, 20.11, 20.12, 20.13, 20.14, 20.15, 20.16, 20.18
- **Configurations:** Systems with internet-exposed management or control planes and exposed ports.
## Vulnerability Description
This is a critical Improper Authentication vulnerability affecting the peering authentication process. A flaw in how the SD-WAN Controller and Manager validate peers allows an unauthenticated, remote attacker to bypass security checks. By successfully exploiting this flaw, an attacker can obtain full administrative privileges on the affected system.
## Exploitation
- **Status:** **Exploited in the wild.** Reports indicate malicious rogue peers are being added to SD-WAN configurations.
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** Critical (Full access to network configurations and data)
- **Integrity:** Critical (Ability to add rogue peers and modify system settings)
- **Availability:** Critical (Potential for total network disruption)
## Remediation
### Patches
Cisco recommends upgrading to the following fixed releases:
- **Rel 20.9:** 20.9.8.2 (Est. Feb 27, 2026)
- **Rel 20.11 / 20.12:** 20.12.6.1
- **Rel 20.12.5:** 20.12.5.3
- **Rel 20.13 / 20.14 / 20.15:** 20.15.4.2
- **Rel 20.16 / 20.18:** 20.18.2.1
- **Versions < 20.9:** Migrate to a supported fixed release.
### Workarounds
- Implement strict network perimeter controls.
- Disable internet-exposed management/control planes where possible.
- Apply Cisco SD-WAN hardening guidance immediately.
## Detection
- **Indicators of Compromise:** Presence of unauthorized "rogue peers" within the SD-WAN configuration.
- **Detection Methods:**
- Audit SD-WAN peer lists for unknown devices.
- Collect and analyze virtual snapshots and system logs.
- Refer to the "ACSC-led Cisco SD-WAN Hunt Guide" for detailed forensic procedures.
## References
- Cisco Security Advisory: hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk
- Canadian Centre for Cyber Security Alert: hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/al26-004-critical-vulnerability-affecting-cisco-catalyst-sd-wan-cve-2026-20127
- Talos Intelligence Blog: hxxps[://]blog[.]talosintelligence[.]com/uat-8616-sd-wan/
- NVD Entry: hxxps[://]nvd[.]nist[.]gov/vuln/detail/CVE-2026-20127