CVE-2026-20245
BaseFortify
Publication date: 2026-06-04
Last updated on: 2026-06-04
Assigner: Cisco Systems, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| cisco | catalyst_sd-wan_manager | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-116 | The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the CLI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). It allows an authenticated local attacker with netadmin privileges to execute arbitrary commands as the root user by supplying a specially crafted file to the system.
The root cause is insufficient validation of user-supplied input, which enables command injection attacks and privilege escalation to root.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow an attacker to execute arbitrary commands with root privileges on the affected system.
This could lead to unauthorized configuration changes, including changes pushed to edge devices, potentially compromising the network infrastructure.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, Cisco recommends upgrading to the fixed software version documented in the security advisory published on May 14, 2026.
Additionally, verify the configuration of the edge devices to ensure no unauthorized changes have been pushed.