[CIVN-2026-0318] Arbitrary File Write Vulnerability in Cisco Catalyst SD-WAN Manager

By Published On: June 17, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Arbitrary File Write Vulnerability in Cisco Catalyst SD-WAN Manager


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: MEDIUM


Software Affected


Cisco Catalyst SD-WAN release prior to 20.9.9.2

Cisco Catalyst SD-WAN release prior to 20.12.7.2

Cisco Catalyst SD-WAN release prior to 20.15.4.5

Cisco Catalyst SD-WAN release prior to 20.15.5.3

Cisco Catalyst SD-WAN release prior to 20.18.3.1

Cisco Catalyst SD-WAN release prior to 26.1.1.2

Overview


A vulnerability has been reported in Cisco Catalyst SD-WAN Manager, which may allow an authenticated remote attacker to create or overwrite arbitrary files on the affected system.


Target Audience:

All end-user organizations and individuals using Cisco Catalyst SD-WAN Manager.


Risk Assessment:

Risk of unauthorized file creation or modification and disruption of services.


Impact Assessment:

Potential for privilege escalation and compromise of system integrity.


Description


Cisco Catalyst SD-WAN Manager (formerly Cisco SD-WAN vManage) is a centralized network management platform used to provision, monitor, and manage Cisco SD-WAN deployments.


A vulnerability exists in the web-based management interface of Cisco Catalyst SD-WAN Manager due to improper validation of user-supplied input. An authenticated remote attacker could exploit this vulnerability by sending crafted HTTP requests to an affected API endpoint of the affected system.


Successful exploitation of this vulnerability could allow authenticated remote attacker to create or overwrite arbitrary files on the underlying file system of the affected device, resulting in privilege escalation including root.


Solution


Apply appropriate security updates and mitigations as mentioned in the vendor advisory:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ



Vendor Information


Cisco

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ


References


 

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ


CVE Name

CVE-2026-20262




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmoyudkACgkQ3jCgcSdc

ys/waQ/9Gmu93+GtBjfe9Aug5t6lAMwhRy3ppS6+N+mmdQMC5gFhHpJ+xVIr+rsS

ABUJWrFFgACPRHVAB4TLra45YvfYVXPRvv8q8VmC/u4matWC5oswb7NtIvFnfhOg

14UhxsNtliVqhTWYCvW+92WAwMXlHQbM5SA8RqSlgiTqiKSa6JSTwcPP/fg3QHub

G0CYD2GQh9wA7OBmZBHUsblK5rnpAOMwAOmZ7+0gsUKekVYeTZPRZmeoaVYUDfo2

xOb0zCH2WQzz7OADhWcFcqvklt51+P0FBgugQMx6dJ0YInKZ7uq5pagB6oEKA/Kg

XFiUfJsyhLX16hooJ22Z7uQlA8Z4x5whmPQt4Bvn3uXGKQFIT5VIcvjSULCoghzN

2+RWj8nJPujQpXiGo87qTu+YHPEM/ucwXmJ1EMrHXR8wK9WbQD4UF86FY+C44JJ5

7aO5gymUWdTiNCBTtxUjBBgZhYaHrfLzumklM2KA4yvnVN3SrY8ZyZtdtg+l0Alm

U7t138dIJDXoX1c9tzZ2RKmIdaNupG1yw3197xkGJ+7e5w9hPKEN9Q5uvp/d79Xx

OqfF8vd9AYgsSheLWPUYQbU6MPuKYl+jIgMrmGFIb3t3zskfVI2QGQW64WfIxFA7

vOnyLB9/JmY7a3/zHXcIa3mmKwqj3MDTfcQYosMPeTO/zDiHQM0=

=5dfR

—–END PGP SIGNATURE—–

Share this article