Actively exploited in the wild. This CVE is on the CISA Known Exploited Vulnerabilities list — treat remediation as urgent. Federal remediation due by 23 Apr 2026.
Catalyst Sd Wan ManagerApplication · Cisco

CVE-2026-20122

MEDIUM · 5.4 CVSS v3.1 Published 2026-02-25
Fix available
A fix is available. Upgrade to 20.9.8.2 / 20.12.5.3 or later.
See remediation →
100/100
Remediation priority · Urgent
In the wild Remotely reachable Zero-click

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · moderate confidence

This is an improper file handling vulnerability in the Cisco Catalyst SD-WAN Manager API that allows authenticated attackers with read-only credentials to overwrite arbitrary files on the local filesystem. The attacker uploads a malicious file via the API, exploiting improper validation to achieve arbitrary file write capability and escalate privileges to the vmanage user.

MitigationApply the Cisco security patch when released. As an interim measure, restrict API access to only necessary personnel, monitor for suspicious API activity, and consider network segmentation to limit exposure.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
Catalyst Sd Wan ManagerApplication
Affected:< 20.9.8.2>= 20.10, < 20.12.5.3>= 20.13, < 20.15.4.2>= 20.16, < 20.18.2.1= 20.12.6

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
Low
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Identify Cisco Catalyst SD-WAN Manager version
    Run 'show version' on the SD-WAN Manager CLI or check the web UI dashboard for the software version. Alternatively, query the API endpoint /dataservice/system/device/serialnumbers or check the About page in the web interface.
    Affected if The installed version falls into any of these ranges: < 20.9.8.2, >= 20.10 but < 20.12.5.3, >= 20.13 but < 20.15.4.2, >= 20.16 but < 20.18.2.1, or equals exactly 20.12.6
  2. Confirm API interface is enabled and accessible
    Verify the SD-WAN Manager API service is running by checking 'show processes' for http or api services, or attempt a local HTTPS connection to port 8443 or 443 where the API typically listens.
    Affected if The API interface is exposed and accepting connections from users or systems that could use compromised read-only credentials
  3. Review API user accounts and privilege levels
    Use the CLI command 'request webui view-user list' or query the /dataservice/admin/user endpoint via API to enumerate all configured users and their assigned roles.
    Affected if Any user account exists with read-only or observer-level privileges that could be exploited to perform the file write operation
  4. Inspect for unexpected files in web root or system directories
    Check the /opt/sdwan/web root directory and /home/vmanage directory for unexpected or recently modified files. Use 'ls -la /opt/sdwan/' and 'ls -la /home/vmanage/' to list contents and modification times.
    Affected if Unexpected files appear, especially scripts, modified configuration files, or newly created executables in these directories that were not placed there by legitimate administration tasks
  5. Audit API request logs for file upload operations
    Review API access logs in /var/log/sdwan/ or the SD-WAN Manager web UI Logs section for POST requests to /dataservice/file/ put or upload endpoints, particularly those originating from read-only user sessions.
    Affected if File upload API calls are observed from read-only accounts, or unusual file upload patterns are logged that indicate exploitation attempts

You are affected if your Cisco Catalyst SD-WAN Manager version is within any of the listed vulnerable ranges and the API is accessible to users with read-only credentials, as the vulnerability allows those users to overwrite arbitrary files.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Upgrade available Upgrade to 20.9.8.2 / 20.12.5.3 / 20.15.4.2 or later
Fixed in 20.9.8.220.12.5.320.15.4.2
Interim mitigation

Apply the Cisco security patch when released. As an interim measure, restrict API access to only necessary personnel, monitor for suspicious API activity, and consider network segmentation to limit exposure.

Recommended fix Moderate confidence

20.18.2.1 (or latest stable release in your version branch: 20.9.8.2+, 20.12.5.3+, 20.15.4.2+, or 20.18.2.1+)

  1. 1. Identify the current installed version of Cisco Catalyst SD-WAN Manager (vManage) by logging into the vManage web UI or running 'show version' in the CLI
  2. 2. Determine which version branch your current installation falls into (< 20.9.x, 20.10-20.11.x, 20.13-20.14.x, or 20.16-20.17.x)
  3. 3. Download the appropriate fixed release from Cisco: 20.9.8.2 or later for 20.9.x, 20.12.5.3 or later for 20.10-20.11.x, 20.15.4.2 or later for 20.13-20.14.x, or 20.18.2.1 or later for 20.16-20.17.x
  4. 4. Review Cisco SD-WAN Manager upgrade documentation for your version path, ensuring proper backup of configuration data
  5. 5. Schedule a maintenance window as the upgrade may require system downtime
  6. 6. Execute the upgrade following Cisco's standard upgrade procedure for SD-WAN Manager
  7. 7. After upgrade, verify the new version is installed and the vManage service is operational
  8. 8. Confirm the vulnerability is remediated by checking that the file upload API properly handles file operations
Caveat SD-WAN Manager upgrades may require downtime and should be performed in a maintenance window; ensure proper configuration backup before upgrading; verify compatibility with connected SD-WAN devices after upgrade

Generated from the published advisory — verify against the referenced sources before acting.

Fix this in Catalyst Sd Wan Manager Exploited in the wild — priority engagement
  • Consultation4.0 h
  • Implementation8.0 h
  • Testing6.0 h
  • Review / QA2.0 h
20.0 hours of engineering $3,500
Get it fixed fast

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $5,600.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2026-20122 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2026-20122 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data