Improper Link Resolution in Cisco Catalyst SD-WAN Software
CVE-2026-20313

7.7HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
5 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-20313?

The Cisco Catalyst SD-WAN has been identified with vulnerabilities concerning improper link resolution before file access, categorized under the Common Weakness Enumeration (CWE) as CWE-1284. This issue could potentially lead to unauthorized access or exposure of sensitive data by mishandling file access requests. In response to this, Cisco has implemented software hardening measures to strengthen the security posture of their SD-WAN solutions.

Affected Version(s)

Cisco Catalyst SD-WAN Controller 20.6.4

Cisco Catalyst SD-WAN Controller 20.9.2

Cisco Catalyst SD-WAN Controller 20.3.6

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.