Arbitrary command execution in Cisco Catalyst SD-WAN Manager (CVE-2026-20245) — root via a crafted file
An output-escaping flaw in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) lets an authenticated local attacker run arbitrary commands as root by supplying a crafted file. CISA listed it as known-exploited (KEV) (CVSS 7.8 High, per NVD).
Key facts
- CVE IDCVE-2026-20245
- CVSS base score7.8 HIGH
- CVSS vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Affected (vendor / product)Cisco Catalyst SD-WAN Manager
- CWECWE-116
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-06-23 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Improper output encoding/escaping (CWE-116) in Cisco Catalyst SD-WAN Manager (formerly vManage)
- An authenticated local attacker can run arbitrary commands as root via a crafted file
- Compromise of the central network-management platform risks propagation to many downstream sites
- Listed in CISA KEV = exploitation confirmed; CVSS 7.8 High, per NVD
- Response: apply Cisco's fix; if not possible, consider disabling the feature / discontinuing use
- Of the 1,687 records held as of 2026-09-01, Cisco accounts for 96 across 41 product names, variants included.
1The Catalyst SD-WAN Manager flaw
CVE-2026-20245 is an improper output encoding/escaping vulnerability (CWE-116) in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). SD-WAN Manager is the platform for centrally managing and controlling a wide-area network (SD-WAN) that connects multiple sites.
2What an authenticated local attacker can do
Per public information, an authenticated local attacker can execute arbitrary commands as root by supplying a crafted file to the affected system. Because the prerequisite is "authenticated and local," it is harder to reach than an unauthenticated remote flaw, but the key concern is that a low-privileged user can reach root.
3What losing the management plane means
Targeting a network-management platform matters greatly: seizing SD-WAN Manager lets an attacker manipulate the configuration of many downstream sites and devices, propagating the attack across the organization's entire network.
4Cisco's 96 records span 41 product names
Cisco is second by vendor among the KEV records this site holds as of 2026-09-01. The entries are not concentrated in one product but spread across many names.
Of the 1,687 records held as of 2026-09-01, Cisco accounts for 96 across 41 product names. Those names carry variants: IOS software, IOS Software, IOS and IOS XE, and IOS and IOS XE Software all appear as separate names, so grouping by product name splits one product into several. Network management platforms matter here: taking SD-WAN Manager allows the configuration of many sites and devices beneath it to be manipulated.
Why it matters
Concerns the network-management platform of organizations running multi-site SD-WAN. Seizing the platform leads directly to organization-wide propagation, so prompt patching, least-privilege management access, and operation-log review are the priorities. It underscores treating the network-control plane as a high-value asset.
FAQ
What is SD-WAN Manager?
If it is "authenticated and local," is the risk low?
What should I do?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).