CVE-2026-20128 | Cisco Catalyst SD-WAN Manager up to 26.1.1 Data Collection Agent password recoverable (cisco-sa-sdwan-authbp-qwCX8D4v / Nessus ID 300000)
A vulnerability categorized as critical has been discovered in Cisco Catalyst SD-WAN Manager. This issue affects some unknown processing of the component Data Collection Agent. Executing a manipulation can lead to storing passwords in a recoverable format.
The identification of this vulnerability is CVE-2026-20128. The attack can only be executed locally. There is no exploit available.
It is advisable to upgrade the affected component.