CVE-2026-20262

MEDIUM KEV

Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-20262 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 15, 2026. EIP tracks 2 public exploits from researchers including fevar54, HORKimhab.

AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2026-20262, a path traversal vulnerability in Cisco Catalyst SD-WAN Manager. The exploit allows authenticated users to write arbitrary files to the system, potentially leading to RCE via WAR file deployment.

Description

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least a lower-privileged, single-task user account.

Exploits (2)

github WORKING POC
by fevar54 · pythonpoc
https://github.com/fevar54/CVE-2026-20262-Cisco-Catalyst-SD-WAN-Manager-Arbitrary-File-Write-

This repository contains a functional Python exploit for CVE-2026-20262, a path traversal vulnerability in Cisco Catalyst SD-WAN Manager. The exploit allows authenticated users to write arbitrary files to the system, potentially leading to RCE via WAR file deployment.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cisco Catalyst SD-WAN Manager (vManage) versions 20.9.x to 20.18.x and 26.1.x
Auth required
Prerequisites: valid credentials with write permissions · access to the vulnerable endpoint
mistral-large-3 · analyzed Jun 17, 2026 Full analysis →
nomisec SUSPICIOUS
by HORKimhab · poc
https://github.com/HORKimhab/CVE-2026-20262

The repository lacks actual exploit code or technical details about CVE-2026-20262, instead providing generic setup instructions and a script to download external content. The README is filled with disclaimers and ethical use statements but no substantive vulnerability analysis.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: unspecified
No auth needed
Prerequisites: none specified
mistral-large-3 · analyzed Jun 16, 2026 Full analysis →

Scores

CVSS v3 6.5
EPSS 0.0768
EPSS Percentile 93.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact partial

Details

CISA KEV 2026-06-15
VulnCheck KEV 2026-06-15
ENISA EUVD EUVD-2026-36733
CWE
CWE-22
Status published
Products (50)
cisco/catalyst_sd-wan_manager < 20.9.9.2
Cisco/Cisco Catalyst SD-WAN Manager 17.2.10
Cisco/Cisco Catalyst SD-WAN Manager 17.2.4
Cisco/Cisco Catalyst SD-WAN Manager 17.2.5
Cisco/Cisco Catalyst SD-WAN Manager 17.2.6
Cisco/Cisco Catalyst SD-WAN Manager 17.2.7
Cisco/Cisco Catalyst SD-WAN Manager 17.2.8
Cisco/Cisco Catalyst SD-WAN Manager 17.2.9
Cisco/Cisco Catalyst SD-WAN Manager 18.2.0
Cisco/Cisco Catalyst SD-WAN Manager 18.3.0
... and 40 more
Published Jun 15, 2026
KEV Added Jun 15, 2026
Tracked Since Jun 15, 2026