CISCO Security Advisory

Published Date: July 21, 2026

CVE: CVE-2026-20245

Advisory Summary

A serious authenticated privilege escalation vulnerability has been identified in Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart), Catalyst SD-WAN Manager (formerly vManage), and Catalyst SD-WAN Validator (formerly vBond). This security flaw stems from insufficient validation of user inputs within the CLI, enabling local attackers with netadmin privileges to upload specially crafted files that can execute arbitrary commands as root.

▶ Impact Level: High
This vulnerability potentially allows root-level access, increasing risk of full system control by attackers.

For all organizations leveraging Cisco Catalyst SD-WAN solutions, prompt action is critical to safeguard your network infrastructure from privilege escalation exploits that threaten the integrity and availability of your SD-WAN environment.

Reference: Vendor Advisory