Cisco SD-WAN Flaw Exploited to Execute Root-Level Commands

Cisco has disclosed a high-severity privilege escalation vulnerability, CVE-2026-20245 (CVSS 7.8), in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that allows authenticated local attackers to execute arbitrary commands as root.

Tracked under advisory cisco-sa-sdwan-privesc-4uxFrdzx and Bug ID CSCwu18563, the flaw resides in the CLI of Cisco Catalyst SD-WAN Manager and is rooted in insufficient validation of user-supplied input classified under CWE-116 (Improper Encoding or Escaping of Output).

An attacker can exploit the vulnerability by uploading a specially crafted file to the system, triggering command injection that escalates privileges to the root user, Cisco said.

Cisco SD-WAN Flaw Exploited

Cisco has observed a limited number of real-world cases in which successful exploitation resulted in unauthorized configuration changes being pushed to SD-WAN edge devices.

CVE-2026-20245 requires the attacker to hold netadmin privileges on the affected system either via valid credentials or by chaining two related vulnerabilities.

The first, CVE-2026-20127 (CVSS 10.0), is a maximum-severity authentication bypass that allows an unauthenticated remote attacker to gain high-privileged internal access by sending crafted requests to the SD-WAN Controller.

The second, CVE-2026-20182 (CVSS 10.0), is another critical authentication bypass in the SD-WAN Controller’s vdaemon service (DTLS/UDP port 12346) that injects an attacker-controlled SSH key into the vmanage-admin account, granting persistent NETCONF access to the control plane.

Threat actor UAT-8616, a highly sophisticated adversary tracked by Cisco Talos, has been observed exploiting both CVE-2026-20127 and CVE-2026-20182 in the wild, with exploitation of CVE-2026-20127 dating back to at least 2023.

Affected Products

The vulnerability impacts all deployment types of Cisco Catalyst SD-WAN Manager regardless of device configuration, including:

  • On-Premises Deployments
  • Cisco SD-WAN Cloud-Pro
  • Cisco SD-WAN Cloud (Cisco Managed)
  • Cisco SD-WAN for Government (FedRAMP)

Organizations should immediately audit /var/log/scripts.log for entries resembling the following pattern:

Apr 15 09:44:57 vmanage vScript: Tenant list upload per vsmart serial number:
/usr/bin/vconfd_script_upload_tenant_list.sh -cli path /home/admin/malicious.csv vpn 0

Defenders should also review SD-WAN Controller authentication logs for entries containing “Accepted publickey for vmanage-admin” originating from unknown or unauthorized IP addresses a key IoC associated with CVE-2026-20182 exploitation.

Since these log entries reflect legitimate commands, according to Cisco, all findings must be correlated with known maintenance windows, authorized IP ranges, and the normal SD-WAN topology to eliminate false positives.

Mitigation

No patch or workaround is currently available. Cisco plans to address the vulnerability in a future release. Until then, organizations should:

  • Upgrade to the fixed software detailed in the related May 14, 2026, SD-WAN Security Advisory
  • Verify edge device configurations post-upgrade
  • Collect admin-tech files before upgrading
  • Contact Cisco TAC immediately if compromise is confirmed, as a software update alone will not remediate an already-compromised system

Organizations running internet-exposed Cisco Catalyst SD-WAN Manager instances should treat this as a priority incident given confirmed active exploitation.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories