In plain language
What this advisory means
Cisco has confirmed a high-severity vulnerability in the command-line interface of three Catalyst SD-WAN control components. A local attacker who already has netadmin privileges can upload a specially crafted file and gain root control of the affected system. Cisco became aware of exploitation in June 2026 and observed limited cases in which configuration changes were pushed to edge devices. Customers should preserve evidence before upgrading, install a fixed release as soon as possible, and check systems and edge-device configurations for compromise.
Technical explanation
How the issue affects the environment
CVE-2026-20245 is an input-validation vulnerability (CWE-116) in the CLI of Cisco Catalyst SD-WAN Controller, Manager, and Validator. A local, authenticated attacker with netadmin privileges can upload a crafted file that causes command injection and arbitrary command execution as root. Netadmin access requires valid credentials or could be obtained through exploitation of CVE-2026-20182 or CVE-2026-20127; Cisco is not aware of successful exploitation through other routes. The vulnerability affects the listed products regardless of configuration and across on-premises, Cloud-Pro, Cisco-managed cloud, and government deployment types. Cisco assigns a CVSS 3.1 base score of 7.8.
Operational impact
Why teams should care
Successful exploitation gives an attacker root-level control of an affected SD-WAN control component, potentially compromising confidentiality, integrity, and availability. Cisco has observed limited cases where exploitation resulted in configuration changes pushed to edge devices. Cisco Catalyst SD-WAN Manager systems exposed to the internet with ports exposed to the internet are at risk of compromise.
Immediate action
Before upgrading, run the request admin-tech command on each SD-WAN control component and retain relevant logs to preserve possible indicators of compromise. Upgrade at the earliest opportunity to the applicable first fixed release documented by Cisco. After upgrading, review the advisory's indicators of compromise and verify edge-device configurations for unauthorized changes. If compromise is confirmed, the software update alone is insufficient; contact Cisco TAC and follow its system-specific remediation instructions.
Affected and fixed releases
Temporary risk reduction
Cisco states that no workaround addresses this vulnerability. Cisco Live Protect provides temporary, partial protection only and is not a fix; full remediation requires upgrading to a fixed release. Before deploying the shield, establish required disaster-recovery operations and any required SD-WAN Manager clusters. New disaster-recovery operations and newly created or expanded Manager clusters will not succeed after shield deployment.
Evidence and validation checklist
- Before upgrading, collect an admin-tech file from every SD-WAN control component using the request admin-tech command.
- Include admin-tech data from edge devices that show recent unauthorized configuration changes.
- Retain relevant logs before upgrading.
- Audit /var/log/scripts.log for tenant-list, vSmart serial-number, or ZTP chassis-number file-upload activity described in Cisco's advisory.
- Assess scripts.log entries against normal operations because the recorded commands may be legitimate and the logs do not distinguish malicious from legitimate use.
- Review internet-exposed Catalyst SD-WAN Managers with exposed ports for evidence of compromise.
- After upgrading, review Cisco's documented indicators of compromise and verify edge-device configurations.
- If suspicious entries cannot be explained or compromise is suspected, preserve the evidence and open a Cisco TAC case.
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
