peter bassill · operator
$ cve CVE-2026-20122 JSON

CVE-2026-20122 KEV

5.4
MEDIUM · CVSS 3.1 · EPSS 25% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2026-04-23.

Description

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.

Scoring

CVSS5.4 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS24.98% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-648
On CISA KEVyes — remediate by 2026-04-23
Public exploitnone known
Published2026-02-25
Last modified2026-06-17

CISA KEV

NameCisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
Added2026-04-20
Due2026-04-23
Vendor / productCisco / Catalyst SD-WAN Manger
Ransomware usenone reported

Affected (1)

VendorProduct
ciscocatalyst sd-wan manager

References

→ the Explorer  ·  watch your stack  ·  NVD