Nxploited/CVE-2026-20182
GitHub: Nxploited/CVE-2026-20182
Stars: 1 | Forks: 0
# CVE-2026-20182
Cisco Catalyst SD-WAN Peering Authentication Bypass
# CVE-2026-20182 — Cisco Catalyst SD-WAN Peering Authentication Bypass
**Assessment tool for authorized testing of Cisco Catalyst SD-WAN Controller / Manager peering authentication bypass (CVE-2026-20182).**
| | |
|---|---|
| **CVE** | CVE-2026-20182 |
| **Severity** | **Critical (CVSS 10.0)** |
| **CVSS 3.1** | `AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H` |
| **Product** | Cisco Catalyst SD-WAN Controller (formerly vSmart) · Cisco Catalyst SD-WAN Manager (formerly vManage) |
| **Issue** | Peering authentication mechanism not enforced correctly |
| **Script** | **`CVE-2026-20182.py`** |
## Vulnerability Summary
**May 2026 advisory:** A flaw in **control-connection handshaking / peering authentication** allows an **unauthenticated remote attacker** to bypass authentication and obtain **high-privileged internal access** on affected systems.
An attacker sends **crafted requests** to the affected system. On success, the attacker may authenticate as an **internal, high-privileged, non-root** account and reach **NETCONF**, enabling manipulation of SD-WAN fabric configuration.
| Item | Detail |
|------|--------|
| **Attack vector** | Network |
| **Privileges required** | None |
| **User interaction** | None |
| **Scope** | Changed |
| **Impact** | Confidentiality, integrity, and availability — **High** |
**Recommendation:** Apply Cisco security fixes per official vendor guidance. Restrict management plane exposure, monitor control-plane connections, and audit SD-WAN controllers for unauthorized configuration changes.
## Contact
**Telegram:** [@KNxploited](https://t.me/KNxploited)
## Console Preview