CVE-2026-20262
MEDIUM KEVCisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
Title source: cnaExploitation Summary
CVE-2026-20262 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 15, 2026. EIP tracks 2 public exploits from researchers including fevar54, HORKimhab.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2026-20262, a path traversal vulnerability in Cisco Catalyst SD-WAN Manager. The exploit allows authenticated users to write arbitrary files to the system, potentially leading to RCE via WAR file deployment.
Description
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least a lower-privileged, single-task user account.
Exploits (2)
This repository contains a functional Python exploit for CVE-2026-20262, a path traversal vulnerability in Cisco Catalyst SD-WAN Manager. The exploit allows authenticated users to write arbitrary files to the system, potentially leading to RCE via WAR file deployment.
The repository lacks actual exploit code or technical details about CVE-2026-20262, instead providing generic setup instructions and a script to download external content. The README is filled with disclaimers and ethical use statements but no substantive vulnerability analysis.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N