Executive brief
Cisco Catalyst SD-WAN Manager, a centralized management platform for enterprise networks, contains a security flaw that allows an authorized user to take full control of the system. By uploading a specially crafted file, an attacker with existing network administrator credentials can gain root-level access, potentially allowing them to alter network configurations or disrupt traffic across connected edge devices. Cisco has reported that this vulnerability has been exploited in the wild to push unauthorized configuration changes to network hardware.
Technical details
A vulnerability in the Command Line Interface (CLI) of Cisco Catalyst SD-WAN Manager (formerly vManage) stems from improper encoding or escaping of output (CWE-116) and insufficient validation of user-supplied input. An attacker with 'netadmin' privileges can exploit this by uploading a crafted file to the system, leading to command injection. Successful exploitation allows the attacker to elevate privileges to the root user. Cisco has confirmed active exploitation in the wild, noting instances where attackers successfully pushed configuration changes to downstream edge devices. A fix was released on May 14, 2026.
Affected products
- Cisco Catalyst SD-WAN Manager All versions prior to May 14, 2026 fix
Timeline
- 2026-05-14: patched: Fixed software documented in Cisco advisory
- 2026-06-04: advisory: Initial NVD publication date
- 2026-06-09: disclosed
- 2026-06-09: exploited: Reported as exploited in the wild in advisory text