PT-2026-46400 · Cisco · Catalyst Sd-Wan Manager

CVE-2026-20245

·

Published

2026-06-04

·

Updated

2026-08-28

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Catalyst SD-WAN Controller (affected versions not specified) Cisco Catalyst SD-WAN Manager (affected versions not specified) Cisco Catalyst SD-WAN Validator (affected versions not specified)
Description A vulnerability in the CLI of the affected systems allows an authenticated local attacker with netadmin privileges to execute arbitrary commands as root. The issue stems from insufficient validation of user-supplied input, specifically when uploading crafted files. In real-world incidents, attackers have used a crafted CSV file (e.g., evil tenant.csv) to modify /etc/passwd and /etc/shadow to create a hidden root account (troot), enabling full control over the SD-WAN environment and the ability to push configuration changes to edge devices. Additionally, some reports indicate a validation failure in the web management daemon where unauthenticated remote attackers can submit crafted HTTP requests with nested system definitions to override active configuration variables and manipulate the control plane.
Recommendations Upgrade to the fixed software documented in the advisory published on May 14, 2026. Verify the configuration of edge devices to ensure no unauthorized changes were made. Check for the existence of unauthorized accounts, such as troot, and audit peer connections. Apply strict ACLs to the SD-WAN Manager interface to drop all inbound traffic except from known-good, static administrative IP addresses. Ensure management portals are not discoverable on the public WAN and route administrative actions through encrypted internal VPNs or secure jump-boxes. Audit web management HTTP access logs for anomalous POST or PUT requests containing uncharacteristic parameter arrays.

Fix

RCE

DoS

LPE

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07857
CVE-2026-20245

Affected Products

Catalyst Sd-Wan Manager