CVE-2026-20245
Cisco SD-WAN Catalyst Manager vulnerability analysis and mitigation

Overview

CVE-2026-20245 is a CLI command injection vulnerability in Cisco Catalyst SD-WAN Controller (formerly vSmart), Cisco Catalyst SD-WAN Manager (formerly vManage), and Cisco Catalyst SD-WAN Validator (formerly vBond) that allows an authenticated local attacker with netadmin privileges to execute arbitrary commands as root by uploading a crafted file. The vulnerability was first published on June 4, 2026, and patches were released on June 12, 2026. Affected versions span multiple release trains including 20.9 through 26.1 branches. It carries a CVSS v3.1 base score of 7.8 (High) (Cisco Advisory, CISA KEV).

Technical details

The root cause is insufficient validation of user-supplied input in the CLI file-handling routines, classified as CWE-116 (Improper Encoding or Escaping of Output). An attacker exploits the vulnerability by uploading a specially crafted file through the CLI, which triggers OS command injection when the file is processed by privileged scripts such as vconfd_script_upload_tenant_list.sh, vconfd_script_upload_vsmart_serial_numbers.sh, or vconfd_script_upload_chassis_number_file.sh. Exploitation requires the attacker to already hold netadmin-level credentials on the affected system — either obtained legitimately or via chained exploitation of CVE-2026-20182 (authentication bypass, CVSS 10.0) or CVE-2026-20127. The vulnerability affects all deployment types including on-premises, Cisco SD-WAN Cloud-Pro, and FedRAMP environments (Cisco Advisory, Github Advisory).

Impact

Successful exploitation grants the attacker full root-level command execution on the affected SD-WAN control plane component, resulting in complete confidentiality, integrity, and availability compromise of the system. Cisco has confirmed limited real-world cases where exploitation led to unauthorized configuration changes being pushed to SD-WAN edge devices, enabling potential network-wide manipulation across the entire SD-WAN fabric. The ability to alter edge device configurations creates significant risk of lateral movement, traffic interception, and persistent access across enterprise WAN infrastructure (Cisco Advisory, CISA KEV).

Exploitation steps

  1. Reconnaissance: Identify internet-exposed Cisco Catalyst SD-WAN Manager, Controller, or Validator instances using network scanning tools or Shodan, targeting vulnerable release trains (e.g., 20.9 through 26.1 branches prior to fixed versions).
  2. Obtain netadmin credentials: Either use valid stolen/leaked netadmin credentials, or chain with CVE-2026-20182 (authentication bypass, CVSS 10.0) or CVE-2026-20127 to gain an authenticated session with netadmin privileges on the target system.
  3. Craft malicious file: Prepare a file containing OS command injection payloads designed to be processed by vulnerable CLI scripts (e.g., vconfd_script_upload_tenant_list.sh, vconfd_script_upload_vsmart_serial_numbers.sh, or vconfd_script_upload_chassis_number_file.sh).
  4. Upload crafted file via CLI: Use the authenticated netadmin session to upload the crafted file to the affected system through the CLI interface, triggering the vulnerable file-processing routine.
  5. Achieve root code execution: The injected commands execute as root due to insufficient input validation, granting full system control.
  6. Push malicious configuration to edge devices: Leverage root access on the SD-WAN Manager to modify and push unauthorized configuration changes to SD-WAN edge devices across the network fabric, enabling persistent access and network manipulation (Cisco Advisory, BleepingComputer).

Indicators of compromise

  • Logs: Entries in /var/log/scripts.log referencing CLI file upload commands such as:
    • vconfd_script_upload_tenant_list.sh -cli path /home/admin/malicious.csv vpn 0
    • vconfd_script_upload_vsmart_serial_numbers.sh -cli path /home/admin/vsmart_serial_numbers_safe.csv
    • vconfd_script_upload_chassis_number_file.sh -cli path /home/admin/chassis_numbers_safe.csv Note: These commands also appear during legitimate operations; context and origin must be assessed.
  • Logs: Entries in /var/log/auth.log showing Accepted publickey for vmanage-admin from unknown or unauthorized IP addresses (indicator of chained CVE-2026-20182 exploitation).
  • Network: Unexpected or unauthorized control connection peering events in SD-WAN logs, particularly vmanage peer-type connections from unrecognized IP addresses or at unusual times.
  • Configuration: Unauthorized or unexpected configuration changes pushed to SD-WAN edge devices, detectable by reviewing edge device configuration history in the SD-WAN Manager UI.
  • Process: Unusual processes spawned with root privileges on SD-WAN control components outside of normal maintenance windows (Cisco Advisory).

Mitigation and workarounds

Cisco has released fixed software versions and confirms no workarounds are available. Organizations must upgrade to a patched release. Fixed versions by release train are:

  • 20.9: 20.9.9.2
  • 20.12.7.x: 20.12.7.2
  • 20.15.4.x: 20.15.4.5
  • 20.15.5.x: 20.15.5.3
  • 20.18: 20.18.3.1
  • 26.1: 26.1.1.2

Before upgrading, Cisco strongly recommends running request admin-tech on all control components to preserve forensic evidence. After upgrading, verify edge device configurations for unauthorized changes. If indicators of compromise are found, contact Cisco TAC for specific remediation steps, as a software update alone will not resolve a confirmed compromise. Restrict netadmin privilege access to trusted administrators only (Cisco Advisory, CISA KEV).

Community reactions

Cisco credited Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan of Mandiant (a Google Cloud division) with discovering and reporting the vulnerability (Cisco Advisory). The vulnerability generated significant media coverage, with BleepingComputer, The Hacker News, The Register, SecurityWeek, and CyberScoop all reporting on active zero-day exploitation before patches were available (BleepingComputer, The Register). Security researchers and the community noted this was described as the 7th Cisco SD-WAN zero-day exploited in 2026, raising concerns about the persistent targeting of Cisco SD-WAN infrastructure. The Qualys Threat Protection team and FortiGuard also published analyses highlighting the active exploitation risk (FortiGuard). Reddit and social media communities expressed alarm at the lack of an initial patch and the chaining potential with other SD-WAN authentication bypass vulnerabilities.

Additional resources


SourceThis report was generated using AI

Related Cisco SD-WAN Catalyst Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20224HIGH8.6
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026
CVE-2026-20245HIGH7.8
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
YesYesJun 04, 2026
CVE-2026-20262MEDIUM6.5
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
YesYesJun 15, 2026
CVE-2026-20210MEDIUM5.4
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026
CVE-2026-20209MEDIUM5.4
  • Cisco SD-WAN Catalyst Manager logoCisco SD-WAN Catalyst Manager
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager
NoYesMay 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management