DCA Password File Disclosure in Cisco Catalyst SD-WAN Manager
CISA: Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
CVSS 3.1
7.5high
EPSS
7%p94
Published
()
KEV added
AI analysis
CVE-2026-20128 is a password-storage flaw (CWE-257, Storing Passwords in a Recoverable Format) in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager, which leaves a credential file containing the DCA user password on affected systems. An unauthenticated, remote attacker can send a crafted HTTP request to read that file and recover the DCA password. With the recovered credentials, the attacker can access another affected system and gain DCA user privileges, enabling chained compromise across SD-WAN management infrastructure. Organizations running Cisco Catalyst SD-WAN Manager releases earlier than 20.18 are affected; releases 20.18 and later are not. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, indicating exploitation in the wild, with an EPSS 30-day exploitation probability of 6.9% (94th percentile); no public proof-of-concept is known, and CISA has issued Emergency Directive 26-03 and hunt-and-hardening guidance for Cisco SD-WAN devices.
What to do: Upgrade Cisco Catalyst SD-WAN Manager to release 20.18 or later, which is not affected. In the meantime, follow CISA's Emergency Directive 26-03 and the 'Hunt & Hardening Guidance for Cisco SD-WAN Devices' to assess exposure, hunt for crafted HTTP requests reading the DCA credential file, and rotate DCA credentials on affected systems; if you use affected cloud-service offerings and mitigations are unavailable, follow applicable BOD 22-01 guidance or discontinue use.
Affected
Cisco Catalyst SD-WAN Manager
Releases earlier than 20.18 (releases 20.18 and later are not affected)
Estimated exposure
large≈10,000–100,000 SD-WAN Manager deployments worldwide (order of tens of thousands) — Cisco is a leading SD-WAN vendor with a large installed base of enterprise branch deployments, and Catalyst SD-WAN Manager (vManage) is typically deployed as one management instance or cluster per organization, often internet-exposed for…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
CISA Known Exploited Vulnerability
Affected
Cisco Catalyst SD-WAN Manager
Required action
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Cisco fixed SD-WAN Controller auth bypass CVE-2026-20127 (CVSS 10) exploited in the wild since 2023, plus several critical and high flaws in SD-WAN Manager.
On 25 February 2026 Cisco released advisories for multiple flaws in Catalyst SD-WAN Controller and SD-WAN Manager, potentially granting administrative access to attackers. CVE-2026-20127 (CVSS 10.0) is an authentication bypass in the Controller's peering authentication mechanism, exploited in the wild since 2023, allowing unauthenticated admin access via NETCONF, rogue device injection, and persistent access. SD-WAN Manager flaws include CVE-2026-20129 (9.8, unauthenticated API auth bypass to netadmin), CVE-2026-20126 (7.8, local privesc to root), CVE-2026-20133 (7.5, info disclosure), CVE-2026-20122 (7.1, arbitrary file overwrite), and CVE-2026-20128 (5.5, DCA info disclosure). CERT-EU recommends patching, capturing forensic evidence, IOC hunting, and restricting management-plane internet exposure.