PT-2026-21952 · Cisco · Cisco Catalyst Sd-Wan Manager
Arthur Vidineyev
·
Published
2026-02-25
·
Updated
2026-04-22
·
CVE-2026-20122
CVSS v2.0
7.5
High
| AV:N/AC:L/Au:S/C:N/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco Catalyst SD-WAN Manager (affected versions not specified)
Description
An issue in the API of Cisco Catalyst SD-WAN Manager, specifically within the Data Collection Agent (DCA) service, results from improper file handling and the incorrect use of privileged application programming interfaces (APIs). An authenticated remote attacker with valid read-only credentials and API access can exploit this by uploading a malicious file to the local file system. This allows the attacker to overwrite arbitrary files, potentially leading to the acquisition of vmanage user privileges and unauthorized access to protected information. This issue has been actively exploited in real-world incidents.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Catalyst Sd-Wan Manager