PT-2026-21952 · Cisco · Cisco Catalyst Sd-Wan Manager

Arthur Vidineyev

·

Published

2026-02-25

·

Updated

2026-04-22

·

CVE-2026-20122

CVSS v2.0

7.5

High

AV:N/AC:L/Au:S/C:N/I:C/A:P
Name of the Vulnerable Software and Affected Versions Cisco Catalyst SD-WAN Manager (affected versions not specified)
Description An issue in the API of Cisco Catalyst SD-WAN Manager, specifically within the Data Collection Agent (DCA) service, results from improper file handling and the incorrect use of privileged application programming interfaces (APIs). An authenticated remote attacker with valid read-only credentials and API access can exploit this by uploading a malicious file to the local file system. This allows the attacker to overwrite arbitrary files, potentially leading to the acquisition of vmanage user privileges and unauthorized access to protected information. This issue has been actively exploited in real-world incidents.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2026-02319
CVE-2026-20122

Affected Products

Cisco Catalyst Sd-Wan Manager