PT-2026-21954 · Cisco · Cisco Catalyst Sd-Wan Manager+1
CVE-2026-20127
·
Published
2026-02-25
·
Updated
2026-06-29
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Catalyst SD-WAN Controller (affected versions not specified)
Cisco Catalyst SD-WAN Manager (affected versions not specified)
Cisco Catalyst SD-WAN Validator (affected versions not specified)
Description
A flaw in the peering authentication mechanism allows an unauthenticated remote attacker to bypass authentication and gain administrative privileges. An attacker can exploit this by sending crafted requests to the system, enabling them to log in to the Cisco Catalyst SD-WAN Controller as a high-privileged internal user. This access allows the use of NETCONF to manipulate the network configuration of the SD-WAN fabric. The attack chain involves obtaining a hash-like string from the endpoint
reports/data/opt/data/containers/config/data-collection-agent/.dca and using it as a password in a POST request to the /jts/authenticated/j security check endpoint. Subsequently, the attacker can upload a malicious file to the /dataservice/smartLicensing/uploadAck endpoint by exploiting a path traversal vulnerability in the filename parameter to deploy a web archive (WAR) file. This issue has been actively exploited in the wild since 2023 by threat actor UAT-8616, who may further escalate privileges to root and suppress logs to maintain persistence.Recommendations
Apply the official patches released by Cisco for Cisco Catalyst SD-WAN Controller, Manager, and Validator.
Restrict external network access to the
reports/data/opt/data/containers/config/data-collection-agent/ directory using WAF or IDS rules.
Audit the /jts/authenticated/j security check endpoint for suspicious external login attempts.
Audit the /dataservice/smartLicensing/uploadAck endpoint for suspicious archive uploads.
Inspect the /deployments folder for unauthorized or suspicious files.Fix
LPE
RCE
DoS
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Catalyst Sd-Wan Controller
Cisco Catalyst Sd-Wan Manager