Cisco has disclosed a high-severity privilege escalation vulnerability, CVE-2026-20245 (CVSS 7.8), in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that allows authenticated local attackers to execute arbitrary commands as root.
Tracked under advisory cisco-sa-sdwan-privesc-4uxFrdzx and Bug ID CSCwu18563, the flaw resides in the CLI of Cisco Catalyst SD-WAN Manager and is rooted in insufficient validation of user-supplied input classified under CWE-116 (Improper Encoding or Escaping of Output).
An attacker can exploit the vulnerability by uploading a specially crafted file to the system, triggering command injection that escalates privileges to the root user, Cisco said.
Cisco SD-WAN Flaw Exploited
Cisco has observed a limited number of real-world cases in which successful exploitation resulted in unauthorized configuration changes being pushed to SD-WAN edge devices.
CVE-2026-20245 requires the attacker to hold netadmin privileges on the affected system either via valid credentials or by chaining two related vulnerabilities.
The first, CVE-2026-20127 (CVSS 10.0), is a maximum-severity authentication bypass that allows an unauthenticated remote attacker to gain high-privileged internal access by sending crafted requests to the SD-WAN Controller.
The second, CVE-2026-20182 (CVSS 10.0), is another critical authentication bypass in the SD-WAN Controller’s vdaemon service (DTLS/UDP port 12346) that injects an attacker-controlled SSH key into the vmanage-admin account, granting persistent NETCONF access to the control plane.
Threat actor UAT-8616, a highly sophisticated adversary tracked by Cisco Talos, has been observed exploiting both CVE-2026-20127 and CVE-2026-20182 in the wild, with exploitation of CVE-2026-20127 dating back to at least 2023.
Affected Products
The vulnerability impacts all deployment types of Cisco Catalyst SD-WAN Manager regardless of device configuration, including:
- On-Premises Deployments
- Cisco SD-WAN Cloud-Pro
- Cisco SD-WAN Cloud (Cisco Managed)
- Cisco SD-WAN for Government (FedRAMP)
Organizations should immediately audit /var/log/scripts.log for entries resembling the following pattern:
Apr 15 09:44:57 vmanage vScript: Tenant list upload per vsmart serial number:
/usr/bin/vconfd_script_upload_tenant_list.sh -cli path /home/admin/malicious.csv vpn 0
Defenders should also review SD-WAN Controller authentication logs for entries containing “Accepted publickey for vmanage-admin” originating from unknown or unauthorized IP addresses a key IoC associated with CVE-2026-20182 exploitation.
Since these log entries reflect legitimate commands, according to Cisco, all findings must be correlated with known maintenance windows, authorized IP ranges, and the normal SD-WAN topology to eliminate false positives.
Mitigation
No patch or workaround is currently available. Cisco plans to address the vulnerability in a future release. Until then, organizations should:
- Upgrade to the fixed software detailed in the related May 14, 2026, SD-WAN Security Advisory
- Verify edge device configurations post-upgrade
- Collect admin-tech files before upgrading
- Contact Cisco TAC immediately if compromise is confirmed, as a software update alone will not remediate an already-compromised system
Organizations running internet-exposed Cisco Catalyst SD-WAN Manager instances should treat this as a priority incident given confirmed active exploitation.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.