PT-2026-49259 · Cisco · Catalyst Sd-Wan Manager
CVE-2026-20262
·
Published
2026-06-15
·
Updated
2026-07-20
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Catalyst SD-WAN Manager (affected versions not specified)
Description
A directory or path traversal issue exists in the web UI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). The flaw occurs because the software does not properly validate user-supplied input during a file upload process. An authenticated remote attacker with at least a lower-privileged, single-task user account can exploit this by sending a crafted HTTP request to an affected API endpoint. This allows the attacker to create or overwrite arbitrary files on the underlying operating system, which can subsequently be used to elevate privileges to root. This issue has been observed being exploited in real-world attacks.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Restrict management access using VPN, Zero Trust architectures, IP allowlisting, and Multi-Factor Authentication (MFA).
Review logs for suspicious file writes, unexpected configuration changes, new accounts, and unusual administrative activity.
Rotate credentials, API keys, and automation tokens if a compromise is suspected.
Monitor for lateral movement and abnormal traffic patterns across connected sites.
RCE
LPE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Catalyst Sd-Wan Manager