PT-2026-49259 · Cisco · Catalyst Sd-Wan Manager

Published

2026-06-15

·

Updated

2026-06-15

·

CVE-2026-20262

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Catalyst SD-WAN Manager (affected versions not specified)
Description A flaw in the web UI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) allows an authenticated, remote attacker to create or overwrite any file on the underlying operating system. This occurs because the software fails to properly validate user-supplied input during a file upload process. An attacker with at least a lower-privileged, single-task user account can exploit this by sending a crafted HTTP request to an affected API endpoint. This issue has been exploited in zero-day attacks to achieve privilege escalation to root.
Recommendations Update to the latest security updates released by Cisco. As a temporary mitigation, restrict access to the file upload API endpoint to only highly trusted administrators.

Fix

LPE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-20262

Affected Products

Catalyst Sd-Wan Manager