Junglewise Threat Intelligence

CVE-2026-20262: Cisco Catalyst SD-WAN Manager arbitrary file write in web UI

CVE-2026-20262 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2026-06-15

Technologies: Cisco Catalyst SD-WAN Manager. Vendors: Cisco.

Executive brief

Cisco Catalyst SD-WAN Manager, a tool used to manage corporate wide-area networks, contains a security flaw that allows an authorized user to manipulate files on the system. By uploading specially crafted data, an attacker could overwrite critical system files or create new ones. This could lead to a total takeover of the management platform, potentially allowing the attacker to gain administrative (root) control over the network infrastructure.

Technical details

A path traversal vulnerability (CWE-22) exists in the web UI of Cisco Catalyst SD-WAN Manager (formerly vManage) due to insufficient validation of user-supplied input during file upload processes. An authenticated, remote attacker with at least low-privileged access can exploit this by sending crafted HTTP requests to specific API endpoints. Successful exploitation allows the attacker to create or overwrite any file on the filesystem. This capability can be leveraged to achieve privilege escalation to root on the underlying operating system. The vulnerability is confirmed to be exploited in the wild.

Affected products

  • Cisco Catalyst SD-WAN Manager

Timeline

  • 2026-06-15: disclosed
  • 2026-06-15: advisory
  • 2026-06-15: exploited: Reported as exploited in the wild at the time of publication.

Related threats