PT-2026-46400 · Cisco · Catalyst Sd-Wan Manager
CVE-2026-20245
·
Published
2026-06-04
·
Updated
2026-07-15
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Catalyst SD-WAN Controller (affected versions not specified)
Cisco Catalyst SD-WAN Manager (affected versions not specified)
Cisco Catalyst SD-WAN Validator (affected versions not specified)
Description
A flaw in the Command Line Interface (CLI) and web management daemon of the affected systems allows an authenticated local attacker with
netadmin privileges to execute arbitrary commands as root. The issue stems from insufficient validation of user-supplied input and improper encoding or escaping of output. An attacker can exploit this by uploading a crafted file, such as a CSV file, to perform command injection and elevate privileges. Real-world exploitation has been observed where attackers used a crafted file named evil tenant.csv to modify /etc/passwd and /etc/shadow to create a hidden root account (troot). In some cases, this led to unauthorized configuration changes being pushed to edge devices. Additionally, some reports indicate that unauthenticated remote attackers may target the management web interface using specially structured API payloads to override configuration variables and manipulate the control plane.Recommendations
Upgrade to the fixed software documented in the Cisco advisory published on May 14, 2026.
Verify the configuration of edge devices to ensure no unauthorized changes were made.
Audit peer connections and system logs for indicators of compromise, specifically searching for the
troot account.
Apply strict Access Control Lists (ACLs) to the management interface to allow traffic only from known, static administrative IP addresses.
Ensure management portals are not discoverable on the public WAN and are accessed exclusively via encrypted internal VPNs or secure jump-boxes.
Export and compare current device profiles and routing parameters against verified backups to identify unauthorized adjustments.Fix
LPE
RCE
DoS
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Catalyst Sd-Wan Manager