Historical catalog analysis: CISA added this entry on April 20, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.
What the vulnerability is
CVE-2026-20128 is a vulnerability in Cisco Catalyst SD-WAN Manager involving the storage of passwords in a recoverable format (CWE-257). This flaw allows an attacker who has already gained authenticated, local access to the system with low privileges to access a credential file for the DCA user located on the filesystem. Successful exploitation enables the attacker to escalate their privileges to those of the DCA user.
Exposure and applicability
This vulnerability specifically affects deployments utilizing Cisco Catalyst SD-WAN Manager. The attack vector is limited to local, authenticated users; it cannot be triggered remotely without prior access to the underlying filesystem. Organizations managing SD-WAN infrastructure should identify all instances of the Manager to determine if they are running versions susceptible to this credential recovery flaw.
Remediation priorities
Based on our analysis, defenders should prioritize remediation based on the level of local access granted to non-administrative users on the Manager appliance. We recommend the following actions:
- Apply Vendor Updates: Prioritize the deployment of patches identified in Cisco Security Advisory cisco-sa-sdwan-authbp-qwCX8D4v. This is the primary method for addressing the underlying storage flaw.
- Implement Hardening Guidance: Review and apply the “Hunt & Hardening Guidance for Cisco SD-WAN Devices” provided by CISA to reduce the overall attack surface of the SD-WAN environment.
- Restrict Local Access: Audit and limit local shell or filesystem access to the absolute minimum number of required administrative accounts to reduce the likelihood of a low-privileged user reaching the DCA credential file.
How to validate remediation
Verification must go beyond confirming a software version number. To ensure exposure is reduced, vulnerability management teams should:
* Consult Vendor Documentation: Refer to the specific Cisco Security Advisory for the authorized method of verifying that the password storage mechanism has been updated.
* Audit Filesystem Permissions: Verify that low-privileged accounts cannot access the sensitive credential files associated with the DCA user.
* Review Configuration State: Ensure that hardening measures outlined in CISA Emergency Directive 26-03 have been applied and are active across all affected nodes.
Limits and open questions
It remains unknown whether this vulnerability has been leveraged by ransomware campaigns. While patching addresses the recoverable format of the passwords, residual risk may exist if other local privilege escalation paths are present or if administrative credentials were compromised prior to remediation. Furthermore, while CISA established a deadline of April 23, 2026, for federal agencies, non-federal organizations must determine their own risk tolerance and patching cadence based on their specific exposure.
Source and editorial note
CVE-2026-20128: Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability · Source date: April 20, 2026 · Retrieved August 31, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Archive date: April 23, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 13, 2026 at 01:02 UTC.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗