PT-2026-49259 · Cisco · Catalyst Sd-Wan Manager

CVE-2026-20262

·

Published

2026-06-15

·

Updated

2026-07-20

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Cisco Catalyst SD-WAN Manager (affected versions not specified)
Description A directory or path traversal issue exists in the web UI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). The flaw occurs because the software does not properly validate user-supplied input during a file upload process. An authenticated remote attacker with at least a lower-privileged, single-task user account can exploit this by sending a crafted HTTP request to an affected API endpoint. This allows the attacker to create or overwrite arbitrary files on the underlying operating system, which can subsequently be used to elevate privileges to root. This issue has been observed being exploited in real-world attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict management access using VPN, Zero Trust architectures, IP allowlisting, and Multi-Factor Authentication (MFA). Review logs for suspicious file writes, unexpected configuration changes, new accounts, and unusual administrative activity. Rotate credentials, API keys, and automation tokens if a compromise is suspected. Monitor for lateral movement and abnormal traffic patterns across connected sites.

RCE

LPE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08313
CVE-2026-20262

Affected Products

Catalyst Sd-Wan Manager