Cisco · Umbrella Virtual Appliance · CVE-2026-20246
**Name of the Vulnerable Software and Affected Versions**
Cisco Umbrella Virtual Appliance (affected versions not specified)
**Description**
An issue in the vmadmin CLI of Cisco Umbrella Virtual Appliance allows an authenticated, local attacker to elevate privileges. This is caused by insufficient validation of user-supplied commands. An attacker with vmadmin privileges can execute specific commands at the CLI to gain root access.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.