CVE-2026-20122
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedA vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · moderate confidenceThis is an improper file handling vulnerability in the Cisco Catalyst SD-WAN Manager API that allows authenticated attackers with read-only credentials to overwrite arbitrary files on the local filesystem. The attacker uploads a malicious file via the API, exploiting improper validation to achieve arbitrary file write capability and escalate privileges to the vmanage user.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.
NVD · CPE data< 20.9.8.2>= 20.10, < 20.12.5.3>= 20.13, < 20.15.4.2>= 20.16, < 20.18.2.1= 20.12.6CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- Low
- Integrity
- Low
- Availability
- None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Identify Cisco Catalyst SD-WAN Manager versionRun 'show version' on the SD-WAN Manager CLI or check the web UI dashboard for the software version. Alternatively, query the API endpoint /dataservice/system/device/serialnumbers or check the About page in the web interface.Affected if The installed version falls into any of these ranges: < 20.9.8.2, >= 20.10 but < 20.12.5.3, >= 20.13 but < 20.15.4.2, >= 20.16 but < 20.18.2.1, or equals exactly 20.12.6
-
Confirm API interface is enabled and accessibleVerify the SD-WAN Manager API service is running by checking 'show processes' for http or api services, or attempt a local HTTPS connection to port 8443 or 443 where the API typically listens.Affected if The API interface is exposed and accepting connections from users or systems that could use compromised read-only credentials
-
Review API user accounts and privilege levelsUse the CLI command 'request webui view-user list' or query the /dataservice/admin/user endpoint via API to enumerate all configured users and their assigned roles.Affected if Any user account exists with read-only or observer-level privileges that could be exploited to perform the file write operation
-
Inspect for unexpected files in web root or system directoriesCheck the /opt/sdwan/web root directory and /home/vmanage directory for unexpected or recently modified files. Use 'ls -la /opt/sdwan/' and 'ls -la /home/vmanage/' to list contents and modification times.Affected if Unexpected files appear, especially scripts, modified configuration files, or newly created executables in these directories that were not placed there by legitimate administration tasks
-
Audit API request logs for file upload operationsReview API access logs in /var/log/sdwan/ or the SD-WAN Manager web UI Logs section for POST requests to /dataservice/file/ put or upload endpoints, particularly those originating from read-only user sessions.Affected if File upload API calls are observed from read-only accounts, or unusual file upload patterns are logged that indicate exploitation attempts
You are affected if your Cisco Catalyst SD-WAN Manager version is within any of the listed vulnerable ranges and the API is accessible to users with read-only credentials, as the vulnerability allows those users to overwrite arbitrary files.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scoped20.9.8.220.12.5.320.15.4.2
Apply the Cisco security patch when released. As an interim measure, restrict API access to only necessary personnel, monitor for suspicious API activity, and consider network segmentation to limit exposure.
20.18.2.1 (or latest stable release in your version branch: 20.9.8.2+, 20.12.5.3+, 20.15.4.2+, or 20.18.2.1+)
- 1. Identify the current installed version of Cisco Catalyst SD-WAN Manager (vManage) by logging into the vManage web UI or running 'show version' in the CLI
- 2. Determine which version branch your current installation falls into (< 20.9.x, 20.10-20.11.x, 20.13-20.14.x, or 20.16-20.17.x)
- 3. Download the appropriate fixed release from Cisco: 20.9.8.2 or later for 20.9.x, 20.12.5.3 or later for 20.10-20.11.x, 20.15.4.2 or later for 20.13-20.14.x, or 20.18.2.1 or later for 20.16-20.17.x
- 4. Review Cisco SD-WAN Manager upgrade documentation for your version path, ensuring proper backup of configuration data
- 5. Schedule a maintenance window as the upgrade may require system downtime
- 6. Execute the upgrade following Cisco's standard upgrade procedure for SD-WAN Manager
- 7. After upgrade, verify the new version is installed and the vManage service is operational
- 8. Confirm the vulnerability is remediated by checking that the file upload API properly handles file operations
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation4.0 h
- Implementation8.0 h
- Testing6.0 h
- Review / QA2.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $5,600.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2026-20122 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2026-20122 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data