CVE-2026-20245 Details
Description
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user. To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of or . Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices. Cisco recommends that customers upgrade to the fixed software that is documented in the that was published on May 14, 2026, and verify the configuration of the edge devices.
A vulnerability exists in the CLI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that allows an authenticated, local attacker to execute arbitrary commands as root. This issue arises from inadequate validation of user-supplied input, enabling attackers with netadmin privileges to upload a crafted file that could be exploited for command injection and privilege escalation. Cisco has noted limited instances where exploitation led to unauthorized configuration changes on edge devices.
Cisco has released software updates addressing this vulnerability. Customers should upgrade to the fixed releases mentioned in the Cisco Catalyst SD-WAN Manager Security Advisory published on May 14, 2026. For additional guidance, consult the Cisco Catalyst SD-WAN Security Advisory - May 2026.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability | Jun 9, 2026 | Jun 23, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-116 | Improper Encoding or Escaping of Output | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco catalyst sd-wan manager | < 20.9.9.1 >= 20.10, < 20.12.5.4 >= 20.12.6, < 20.12.6.2 >= 20.13, < 20.15.4.4 >= 20.15.5, < 20.15.5.2 >= 20.16, < 20.18.2.2 >= 26.1, < 26.1.1.1 20.12.7 |
CPE
Remediation
| |
| cisco sd-wan vsmart controller | < 20.9.9.1 >= 20.10, < 20.12.5.4 >= 20.12.6, < 20.12.6.2 >= 20.13, < 20.15.4.4 >= 20.15.5, < 20.15.5.2 >= 20.16, < 20.18.2.2 >= 26.1, < 26.1.1.1 20.12.7 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jul 21, 2026 | Modified Analysis | [email protected] |
| Jul 21, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2026 | Initial Analysis | [email protected] |
| Jun 9, 2026 | CVE Modified | [email protected] |
| Jun 9, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jun 4, 2026 | New CVE Received | [email protected] |