Security Advisory Desk
highQCS priority 94/100Cisco

Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability

Cisco has confirmed a high-severity vulnerability in the command-line interface of three Catalyst SD-WAN control components. A local attacker who already has netadmin privileges can upload a specially crafted file and gain root control of the affected system. Cisco became aware of exploitation in June 2026 and observed limited cases in which configuration changes were pushed to edge devices. Customers should preserve evidence before upgrading, install a fixed release as soon as possible, and check systems and edge-device configurations for compromise.

Published 21/7/2026, 4:01:27 pmVerified 29/7/2026, 6:17:38 pmRevision 2
Cisco high network security advisory visual

In plain language

What this advisory means

Cisco has confirmed a high-severity vulnerability in the command-line interface of three Catalyst SD-WAN control components. A local attacker who already has netadmin privileges can upload a specially crafted file and gain root control of the affected system. Cisco became aware of exploitation in June 2026 and observed limited cases in which configuration changes were pushed to edge devices. Customers should preserve evidence before upgrading, install a fixed release as soon as possible, and check systems and edge-device configurations for compromise.

Technical explanation

How the issue affects the environment

CVE-2026-20245 is an input-validation vulnerability (CWE-116) in the CLI of Cisco Catalyst SD-WAN Controller, Manager, and Validator. A local, authenticated attacker with netadmin privileges can upload a crafted file that causes command injection and arbitrary command execution as root. Netadmin access requires valid credentials or could be obtained through exploitation of CVE-2026-20182 or CVE-2026-20127; Cisco is not aware of successful exploitation through other routes. The vulnerability affects the listed products regardless of configuration and across on-premises, Cloud-Pro, Cisco-managed cloud, and government deployment types. Cisco assigns a CVSS 3.1 base score of 7.8.

Operational impact

Why teams should care

Successful exploitation gives an attacker root-level control of an affected SD-WAN control component, potentially compromising confidentiality, integrity, and availability. Cisco has observed limited cases where exploitation resulted in configuration changes pushed to edge devices. Cisco Catalyst SD-WAN Manager systems exposed to the internet with ports exposed to the internet are at risk of compromise.

Immediate action

Before upgrading, run the request admin-tech command on each SD-WAN control component and retain relevant logs to preserve possible indicators of compromise. Upgrade at the earliest opportunity to the applicable first fixed release documented by Cisco. After upgrading, review the advisory's indicators of compromise and verify edge-device configurations for unauthorized changes. If compromise is confirmed, the software update alone is insufficient; contact Cisco TAC and follow its system-specific remediation instructions.

Affected and fixed releases

Affected versions20.9.9.1 and earlier, 20.12.7.1 and earlier, 20.15.4.4 and earlier, 20.15.5.2 and earlier, 20.18.2.2 and earlier, 20.18.3, 26.1.1.1 and earlier
Fixed versions20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2

Temporary risk reduction

Cisco states that no workaround addresses this vulnerability. Cisco Live Protect provides temporary, partial protection only and is not a fix; full remediation requires upgrading to a fixed release. Before deploying the shield, establish required disaster-recovery operations and any required SD-WAN Manager clusters. New disaster-recovery operations and newly created or expanded Manager clusters will not succeed after shield deployment.

Evidence and validation checklist

  • Before upgrading, collect an admin-tech file from every SD-WAN control component using the request admin-tech command.
  • Include admin-tech data from edge devices that show recent unauthorized configuration changes.
  • Retain relevant logs before upgrading.
  • Audit /var/log/scripts.log for tenant-list, vSmart serial-number, or ZTP chassis-number file-upload activity described in Cisco's advisory.
  • Assess scripts.log entries against normal operations because the recorded commands may be legitimate and the logs do not distinguish malicious from legitimate use.
  • Review internet-exposed Catalyst SD-WAN Managers with exposed ports for evidence of compromise.
  • After upgrading, review Cisco's documented indicators of compromise and verify edge-device configurations.
  • If suspicious entries cannot be explained or compromise is suspected, preserve the evidence and open a Cisco TAC case.

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source