
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20245 is a CLI command injection vulnerability in Cisco Catalyst SD-WAN Controller (formerly vSmart), Cisco Catalyst SD-WAN Manager (formerly vManage), and Cisco Catalyst SD-WAN Validator (formerly vBond) that allows an authenticated local attacker with netadmin privileges to execute arbitrary commands as root by uploading a crafted file. The vulnerability was first published on June 4, 2026, and patches were released on June 12, 2026. Affected versions span multiple release trains including 20.9 through 26.1 branches. It carries a CVSS v3.1 base score of 7.8 (High) (Cisco Advisory, CISA KEV).
The root cause is insufficient validation of user-supplied input in the CLI file-handling routines, classified as CWE-116 (Improper Encoding or Escaping of Output). An attacker exploits the vulnerability by uploading a specially crafted file through the CLI, which triggers OS command injection when the file is processed by privileged scripts such as vconfd_script_upload_tenant_list.sh, vconfd_script_upload_vsmart_serial_numbers.sh, or vconfd_script_upload_chassis_number_file.sh. Exploitation requires the attacker to already hold netadmin-level credentials on the affected system — either obtained legitimately or via chained exploitation of CVE-2026-20182 (authentication bypass, CVSS 10.0) or CVE-2026-20127. The vulnerability affects all deployment types including on-premises, Cisco SD-WAN Cloud-Pro, and FedRAMP environments (Cisco Advisory, Github Advisory).
Successful exploitation grants the attacker full root-level command execution on the affected SD-WAN control plane component, resulting in complete confidentiality, integrity, and availability compromise of the system. Cisco has confirmed limited real-world cases where exploitation led to unauthorized configuration changes being pushed to SD-WAN edge devices, enabling potential network-wide manipulation across the entire SD-WAN fabric. The ability to alter edge device configurations creates significant risk of lateral movement, traffic interception, and persistent access across enterprise WAN infrastructure (Cisco Advisory, CISA KEV).
vconfd_script_upload_tenant_list.sh, vconfd_script_upload_vsmart_serial_numbers.sh, or vconfd_script_upload_chassis_number_file.sh)./var/log/scripts.log referencing CLI file upload commands such as:vconfd_script_upload_tenant_list.sh -cli path /home/admin/malicious.csv vpn 0vconfd_script_upload_vsmart_serial_numbers.sh -cli path /home/admin/vsmart_serial_numbers_safe.csvvconfd_script_upload_chassis_number_file.sh -cli path /home/admin/chassis_numbers_safe.csv
Note: These commands also appear during legitimate operations; context and origin must be assessed./var/log/auth.log showing Accepted publickey for vmanage-admin from unknown or unauthorized IP addresses (indicator of chained CVE-2026-20182 exploitation).vmanage peer-type connections from unrecognized IP addresses or at unusual times.Cisco has released fixed software versions and confirms no workarounds are available. Organizations must upgrade to a patched release. Fixed versions by release train are:
Before upgrading, Cisco strongly recommends running request admin-tech on all control components to preserve forensic evidence. After upgrading, verify edge device configurations for unauthorized changes. If indicators of compromise are found, contact Cisco TAC for specific remediation steps, as a software update alone will not resolve a confirmed compromise. Restrict netadmin privilege access to trusted administrators only (Cisco Advisory, CISA KEV).
Cisco credited Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan of Mandiant (a Google Cloud division) with discovering and reporting the vulnerability (Cisco Advisory). The vulnerability generated significant media coverage, with BleepingComputer, The Hacker News, The Register, SecurityWeek, and CyberScoop all reporting on active zero-day exploitation before patches were available (BleepingComputer, The Register). Security researchers and the community noted this was described as the 7th Cisco SD-WAN zero-day exploited in 2026, raising concerns about the persistent targeting of Cisco SD-WAN infrastructure. The Qualys Threat Protection team and FortiGuard also published analyses highlighting the active exploitation risk (FortiGuard). Reddit and social media communities expressed alarm at the lack of an initial patch and the chaining potential with other SD-WAN authentication bypass vulnerabilities.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."