Junglewise Threat Intelligence

CVE-2026-20122: Cisco Catalyst SD-WAN Manager arbitrary file overwrite via API

CVE-2026-20122 · Severity: critical · CVSS 5.4 · Exploited in the wild · Published 2026-04-20

Technologies: Cisco Catalyst SD-WAN Manager. Vendors: Cisco.

Executive brief

Cisco Catalyst SD-WAN Manager is a centralized management platform used to configure and monitor enterprise networks. A vulnerability in its programming interface allows an authorized user with basic access to upload files that can overwrite critical system data. If exploited, an attacker could gain elevated administrative control over the management platform, potentially disrupting network operations or accessing sensitive configuration data.

Technical details

A vulnerability in the API interface of Cisco Catalyst SD-WAN Manager (formerly vManage) stems from improper file handling and the incorrect use of privileged APIs (CWE-648). An authenticated, remote attacker with at least read-only credentials and API access can exploit this by uploading malicious files to the local file system. This can lead to an arbitrary file overwrite, allowing the attacker to escalate privileges to the 'vmanage' user level. This vulnerability has been observed being exploited in the wild. Patches are available in versions 20.9.8.2, 20.12.5.3, 20.15.4.2, and 20.18.2.1.

Affected products

  • Cisco Catalyst SD-WAN Manager < 20.9.8.2, 20.10.x < 20.12.5.3, 20.13.x < 20.15.4.2, 20.16.x < 20.18.2.1

Timeline

  • 2026-02-25: disclosed: Initial disclosure by Cisco Systems
  • 2026-04-20: advisory: NVD publication and CISA KEV addition
  • 2026-04-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2026-04-20: exploited: Confirmed active exploitation in the wild

Related threats