---
id: CVE-2026-20108
title: "A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device.\r\n\r…"
summary: "A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device.\r\n\r…"
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: cisco
product: catalyst_sd-wan_manager
affected:
  - 'catalyst_sd-wan_manager >= 20.12, < 20.12.5.3'
  - 'catalyst_sd-wan_manager >= 20.13, < 20.15.4.2'
  - 'catalyst_sd-wan_manager >= 20.16, < 20.18.2.1'
  - catalyst_sd-wan_manager = 20.12.6
patched:
  - catalyst_sd-wan_manager 20.18.2.1
published: '2026-03-25'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20108'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-xss-ZqkhP9W9
    label: psirt@cisco.com
tags:
  - nvd
epss: 0.00162
epssPercentile: 0.05859
ingestedAt: '2026-06-29T21:48:47.440Z'
---

## Overview

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device.
 This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of the web-based management interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

## Affected

- `catalyst_sd-wan_manager >= 20.12, < 20.12.5.3`
- `catalyst_sd-wan_manager >= 20.13, < 20.15.4.2`
- `catalyst_sd-wan_manager >= 20.16, < 20.18.2.1`
- `catalyst_sd-wan_manager = 20.12.6`

## Remediation

Upgrade past the affected range:

- `catalyst_sd-wan_manager 20.18.2.1`
