Vulnerability record · CVE-2026-20262 · published 15 June 2026
CVE-2026-20262: Cisco Catalyst SD-WAN Manager path traversal in file upload
Cisco · Catalyst Sd Wan Manager
Cisco Catalyst SD-WAN Manager (formerly vManage) fails to properly validate user-supplied input during a file upload process, allowing path traversal (CWE-22). An authenticated remote attacker with at least a low-privileged, single-task account can create or overwrite arbitrary files on the underlying filesystem. Because the written file can later be used to elevate to root, the flaw undermines the appliance's privilege boundary even though it requires credentials.
Description
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least a lower-privileged, single-task user account.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityThe flaw requires authentication but allows arbitrary file write leading to root escalation and is listed in CISA KEV with a near-term remediation deadline.
What it is
Cisco Catalyst SD-WAN Manager (formerly vManage) fails to properly validate user-supplied input during a file upload process, allowing path traversal (CWE-22). An authenticated remote attacker with at least a low-privileged, single-task account can create or overwrite arbitrary files on the underlying filesystem. Because the written file can later be used to elevate to root, the flaw undermines the appliance's privilege boundary even though it requires credentials.
Impact
An attacker gains the ability to write or overwrite any file on the affected system's filesystem, which can be leveraged to escalate privileges to root. This gives a low-privileged user a path to full control of the SD-WAN management appliance.
Attack surface
Reached remotely over the network via a crafted HTTP request to an affected API endpoint of the web UI. Authentication is required, but only a lower-privileged single-task account is needed; no user interaction is required.
Exploitation
CVE-2026-20262 was added to CISA KEV on 2026-06-15 with a remediation due date of 2026-06-29, indicating known exploitation in the wild. EPSS gives a 30-day exploitation probability of 0.28171 (98th percentile), and no ransomware campaign use is documented.
What to do
- Apply the vendor fix per the Cisco security advisory for CVE-2026-20262 as the first action.
- Follow CISA BOD 26-04 guidance and the KEV required action, including the 2026-06-29 due date.
- Restrict and audit accounts holding low-privileged single-task roles; remove unused or unnecessary accounts.
- Limit network exposure of the SD-WAN Manager web UI and API endpoints to trusted management networks.
- If mitigations are unavailable, evaluate internet exposure and consider discontinuing use of the product per CISA guidance.
Detection
- Monitor web UI and API file upload requests for path traversal sequences or unexpected absolute paths in filenames.
- Alert on creation or modification of files outside expected upload directories on SD-WAN Manager hosts.
- Audit authentication logs for low-privileged single-task accounts performing upload or API operations.
- Hunt for post-exploitation file writes followed by privilege escalation activity on the appliance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-20262 to the Known Exploited Vulnerabilities catalog on 15 June 2026 as "Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 29 June 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20262 | US Government Resource |
Track CVE-2026-20262 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-20262), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.