Cisco Catalyst SD-WAN Manager ... Note

Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability

A high-severity vulnerability, CVE-2026-20245, has been identified in the CLI of Cisco Catalyst SD-WAN Manager. This flaw allows an authenticated, local attacker with netadmin privileges to execute arbitrary commands as root. The vulnerability stems from insufficient validation of user-supplied input, enabling command injection attacks. An attacker could exploit this by uploading a crafted file to the system. Cisco is aware of limited instances where exploitation led to configuration changes on edge devices. There are currently no workarounds available for this vulnerability. Cisco has not yet released software updates to address the issue. They recommend customers upgrade to a fixed software release documented in their advisory. Before upgrading, it is crucial to collect admin-tech files from control components for forensic analysis. After upgrading, customers should verify system integrity by checking logs for indicators of compromise. If compromise is confirmed, Cisco TAC will provide further remediation steps.