Record summary

CVE-2026-20122 has a selected CVSS score of 5.4 (medium). CISA lists CVE-2026-20122 in KEV.

Description

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Apr 20, 2026 · CISA
VulnCheck KEV
Listed · Mar 5, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 5, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Default status: unknown

CVE List20.1.12affected
19.2.1affected
18.4.4affected
18.4.5affected
20.1.1.1affected
20.1.1affected
19.3.0affected
19.2.2affected
19.2.099affected
18.3.6affected
18.3.7affected
19.2.0affected
Showing 12 of 335 version ranges

References

3