Skip to content

CVE-2026-20127

Improper Authentication — is CVE-2026-20127real, exploitable, or a false positive? Here's the community ground truth.

Critical · CVSS 10EPSS 48.2%CISA KEVCWE-287 · Improper Authentication

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. 

Published

Embed this verdict
TruePositive verdict for CVE-2026-20127
Markdown
[![TruePositive verdict](https://www.truepositive.app/cve/CVE-2026-20127/badge.svg)](https://www.truepositive.app/cve/CVE-2026-20127)
HTML
<a href="https://www.truepositive.app/cve/CVE-2026-20127"><img src="https://www.truepositive.app/cve/CVE-2026-20127/badge.svg" alt="TruePositive verdict for CVE-2026-20127"></a>

Live badge — updates automatically as the community verdict changes.

Community ground truth

Community verdict

3 verdicts
Not a real issue

Includes TruePositive's curated baseline from public sources — community verdicts accrue on top.

to add your verdict.

Community real-world severity: Critical (Critical 3) — CVSS base score 10

In line with its CVSS base score.

Field notes & remediation

Verdicts are the quick signal — notes are the evidence and fixes behind them.

  • 0
    Field note · Lin WeiCurated

    Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability — Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. Listed in the CISA KEV catalog (added 2026-02-25) — confirmed exploited in the wild, not theoretical. FIRST EPSS puts the chance of exploitation in the next 30 days at ~48%. Treat it as real and prioritize remediation over triage.

  • 0
    Remediation · Nadia PetrovaCurated

    Required action for Cisco Catalyst SD-WAN Controller and Manager: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. CISA set a federal remediation due date of 2026-02-27. After patching, verify the vulnerable path is no longer reachable before closing the finding.

Same weaknessCWE-287 · Improper Authentication.