CVE-2026-20127
About
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
Rainforest analyst review
This is an authentication-bypass flaw in the peering authentication used among Cisco's Catalyst SD-WAN control-plane components, the Controller (formerly vSmart), Manager (formerly vManage), and Validator (formerly vBond). The mechanism that authenticates peers in the SD-WAN fabric does not work correctly, so an unauthenticated remote attacker who sends crafted requests can bypass it and log in as an internal, high-privileged account. From there the attacker reaches NETCONF and can manipulate the network configuration of the entire SD-WAN fabric.
These controllers are the brain of a software-defined WAN, orchestrating routing and policy across every site in the fabric, so administrative access to them is administrative access to the organization's wide-area network topology and traffic flows. An attacker able to rewrite fabric configuration can reroute, intercept, or sever connectivity across all managed sites, making this a whole-network compromise rather than a single-device issue. Apply Cisco's fixed releases for the Controller, Manager, and Validator as an urgent priority, keep these control-plane systems on isolated management networks unreachable from untrusted sources, and audit NETCONF activity and configuration changes for unauthorized modifications on any exposed instance.
References
Related CVEs
Frequently asked questions
What is CVE-2026-20127?
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
How severe is CVE-2026-20127?
CVE-2026-20127 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.
How is CVE-2026-20127 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2026-20127?
Public advisories list the following as affected: catalyst sd-wan manager, sd-wan vbond orchestrator, sd-wan vsmart controller. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2026-20127?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
