CVE-2026-20122
Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability
Record summary
CVE-2026-20122 has a selected CVSS score of 5.4 (medium). CISA lists CVE-2026-20122 in KEV.
Description
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
Exploitation context
Known exploitation
- CISA KEV
- Listed · Apr 20, 2026 · CISA
- VulnCheck KEV
- Listed · Mar 5, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 5, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Catalyst SD-WAN MangerBrowse Cisco / Catalyst SD-WAN Manger | CISA | Version data not supplied | |
Cisco Catalyst SD-WAN ManagerBrowse Cisco / Cisco Catalyst SD-WAN ManagerDefault status: unknown | CVE List | 20.1.12 | affected |
| 19.2.1 | affected | ||
| 18.4.4 | affected | ||
| 18.4.5 | affected | ||
| 20.1.1.1 | affected | ||
| 20.1.1 | affected | ||
| 19.3.0 | affected | ||
| 19.2.2 | affected | ||
| 19.2.099 | affected | ||
| 18.3.6 | affected | ||
| 18.3.7 | affected | ||
| 19.2.0 | affected | ||
| Showing 12 of 335 version ranges | |||